Hi, I am trying to get list of logs where the time duration value is in the top 95th percentile of all duration values. Here is what I got but it's not accepting this query:
| json "logStream" as logStream
| json "message" as message
| parse "@*:" as app
| parse "duration: *ms" as duration | pct(duration, 95) as percentile
| where duration>percentile
The error I am getting is "Field duration not found, please check the spelling and try again.".
I tried this, also not working complaining the no definition found for function:
| where duration>(pct(duration, 95))
Please sign in to leave a comment.