How to filter logs based on event A occurring but not event B


1 comment

  • Avatar
    Shobhit Garg

    Hi Piyush,

    You have not mentioned the timerange, but what you can make a query like below, here the assumption is that EventA will always happen. I mean there wont be a case where eventB happens but eventA wont.

    User1   Event1
    userA - eventA
    userA - eventB
    userA - eventA

    userB - eventA
    userB - eventA
    userB - eventA

    Lets say have you have parsed User1 and Event1 fields like above

    | count by user1, event1

    | count by user1

    | where _count=1





    Comment actions Permalink

Please sign in to leave a comment.