How to do subquery?

Comments

1 comment

  • Avatar
    Akash Kadakia

    Hi Jeff,

    Are there any logs in /oracle/queue* where there is no orgId field present? I would try the below query to filter on events with the orgId field.

    _sourceCategory=oracle/queue/* orgId
    [subquery:_sourceCategory=oracle/queue/* orgId
    | parse regex field=json_message "^OMP: (?<metric>.*)" 
    | json auto field=metric 
    | where orgId="XXXXXXXX" 
    | count by requestID 
    | compose requestID keywords

    | json_level=ERROR
    | timeslice 1m 
    | count by _sourceCategory

     

    Akash

    0
    Comment actions Permalink

Please sign in to leave a comment.