I have a problem in which I want to know when a certain FieldB changes value while another FieldA remains constant across many log entries. I transactionize FieldA to create groupings, and while I can see the FieldB values, I want to then run a query to only show groups where the distinct count of FieldBs is greater than 1. Reading the docs it appears I can run a subquery, but I cannot get it to work. I either get syntax error, or the scope of the count is beyond the grouping The below example yields a distinct count beyond the scope of the group created by the transactionize. "GET /api/transaction/" | parse "GET /api/transaction/*?deviceid=* " as FieldA, FieldB |transactionize FieldA (merge FieldA, FieldB ) | count_distinct(FieldB)
Please sign in to leave a comment.