In SumoLogic Is it possible to do search for multiple logs and do some arithmetic on it like
("Log Message1 OR "Log Message2")
count("Log Message1") as msg1
count("Log Message2") as msg2
(msg1-msg2) as msg3
In splunk I used something like
| eval msg1=if(like(line, "%Log Message1%"), 1, 0)
| eval msg2=if(like(line, "%Log Message1%"), 1, 0)
| eval msg3=msg1-msg2
| stats sum(msg1) as msg1
| stats sum(msg2) as msg2
| stats sum(msg3) as msg3
Just recently moved to sumologic and I couldnt find an equvalent way to do this.
Please sign in to leave a comment.