The equal function provides a filter for events that have two fields with the same value.
The parameters to the equal function are field names. Only two field names may be specified. For example:
equal(rule,program)
Result: would return only results that included a rule and a program field that contained the same value.
Note
This function is only supported in rules. It will not work in search.