Adding Relevance Condition

Hello team,

I am trying to work on this code but not sure where to put the condition to filter only the machines with Win2019 OS version:

<?relevance concatenation of trs of ( td of (if ((name of item 0 of it | "") != "") then (name of item 0 of it | "Unknown") else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 2 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 2 of it)) else if (exists values whose (it as string != "" AND it as string contains ".") of results (item 0 of it, elements of item 1 of it)) then (following text of first "." of (concatenation "" of values whose (it as string != "" AND it as string contains ".") of results (item 0 of it, elements of item 1 of it))) else if ((name of item 0 of it | "") contains ".") then (following text of first "." of (name of item 0 of it | "")) else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 3 of it)) then (concatenation "; " of values whose (it as string != "") of results (item 0 of it, item 3 of it)) else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 4 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 4 of it)) else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 5 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 5 of it)) else "Unknown") & td of (((month of item 1 of it as two digits as string) & "/" & (day_of_month of item 1 of it as two digits as string) & "/" & (year of item 1 of it as string) & " " & (two digit hour of time of item 0 of it) & ":" & (two digit minute of time of item 0 of it) & ":" & (two digit second of time of item 0 of it)) of (time (local time zone) of it, date (local time zone) of it) of (last report time of item 0 of it) | "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 6 of it)) then (if ((concatenation "" of values whose (it as string != "") of results (item 0 of it, item 6 of it)) contains " day") then (preceding text of first " " of (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 6 of it))) else "0") else "Unknown") & td of ((((now - last report time of item 0 of it) / day) as string) | "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 7 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 7 of it)) else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 8 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 8 of it)) else "Unknown") & td of (if (exists values whose (it as string != "") of results (item 0 of it, item 9 of it)) then (concatenation "" of values whose (it as string != "") of results (item 0 of it, item 9 of it)) else "Unknown") ) of (elements of item 0 of it, item 1 of it, item 2 of it, item 3 of it, item 4 of it, item 5 of it, item 6 of it, item 7 of it, item 8 of it, item 9 of it) of ( set of bes computers, set of bes properties whose (name of it as lowercase = "dns name"), bes property "Domain_Windows_Unix", bes property "IP Address (Primary)", bes property "Agent Version", bes property "OS", bes property "Uptime of Operating System", bes property "Relay", bes property "Configured Relay - Primary", bes property "Configured Relay - Secondary" ) ?>

Tried adding the condition from here:

but getting the error:

The operator "results from" is not defined.

Any help will be very much appreciated. Thank you in advance

Computer Name Domain IP Address Client Version OS Last Report Time Uptime Days Days Offline Relay Primary Relay Secondary Relay

Well, I would say that you don’t want to structure it this way cause as soon as you start nesting queries (results of.. is like a nested query), performance will go bad in a hurry. So what I would do is apply the filter on the computer set level because the OS specifically is a native sub-inspector and you do not need to go to property at all. So you can do something like:

set of bes computers whose (operating system of it starts with "Win2"), 
set of bes properties whose (name of it as lowercase = "dns name"), 
bes property "Domain_Windows_Unix", 
bes property "IP Address (Primary)", 
bes property "Agent Version", 
bes property "OS", 
bes property "Uptime of Operating System", 
bes property "Relay", 
bes property "Configured Relay - Primary", 
bes property "Configured Relay - Secondary"

Also, I would convert the bes property “xyz” to set of bes properties whose (name of it = “xyz”), as it is much faster performance-wise and it scales better.

2 Likes

Hello Angel,

Thanks a lot!! that helped with the query and it filtered the correct servers and was also able to add other custom properties.

Not sure I understand this one “convert the bes property “xyz” to set of bes properties whose (name of it = “xyz”)“

Do you mean change the remaining “bes property xyz” to “set of bes property xyz”?

set of bes property "Domain_Windows_Unix",
set of bes property "IP Address (Primary)",

.

.

.

set of bes property "Configured Relay - Secondary"

Yes, that’s what I meant. set of bes properties, even if the set contains just a single property is much faster than “bes property” itself.