If logs are missing return new field

Comments

1 comment

  • Official comment
    Avatar
    Nick Wilson

    Hi Istvan,

    I recommend moving your scope down to another "if" statement so you can flag it and max by that flag. Something like:

    *
    | if(_collector="test" AND _sourcecategory="test" AND service_name="something", 1, 0) as scope
    | max(response_time) by scope
    | if(isNull(_max), 0, _max) as latency
    | fields latency

    This is the concept for the approach I would take. Let me know if that helps!

    Thanks,
    Nick
    Customer Success, Sumo Logic

    Comment actions Permalink

Please sign in to leave a comment.