Question on advanced search req

Comments

2 comments

  • Avatar
    Michael Floyd
    @Pavan Dusi Have tried asking this in the Slack channel?
    0
    Comment actions Permalink
  • Avatar
    Mario Sanchez
    Pavan, Is errormesg unique, and would T1.errormesg = t2.errormesg? If so, there could be an easy way to do it: _collector=PRDLOGS AND _source=PRDMWAPI AND "CUSTOMSITENAME" | parse regex "pcall\|(?.*?)customfiles.MiddlewareApi.*?ResponseTime time=(?.*?),transactionType=(?.*?)\.(?!.*\.)" nodrop | parse regex "ERROR .*pcall\|(?.*?)customfiles.MiddlewareApi" | count by errormesg | where count < 2 The nodrop option ensures that messages that do not follow the format of the first regex statement are not dropped, but instead, are passed on to the next regex statement. Cheers, Mario
    0
    Comment actions Permalink

Please sign in to leave a comment.