If logs are missing return new field


1 comment

  • Official comment
    Nick Wilson

    Hi Istvan,

    I recommend moving your scope down to another "if" statement so you can flag it and max by that flag. Something like:

    | if(_collector="test" AND _sourcecategory="test" AND service_name="something", 1, 0) as scope
    | max(response_time) by scope
    | if(isNull(_max), 0, _max) as latency
    | fields latency

    This is the concept for the approach I would take. Let me know if that helps!

    Customer Success, Sumo Logic

    Comment actions Permalink

Please sign in to leave a comment.