Hi all,
What would be a simply approach to creating an alert based on the following log data:
The objective is to send an alert if the "Return Code" does not equal the number "1"
# Reporting Started #
#####################
# Processing task 1
# Processing task 2
# Processing task 3
#####################
# Return Code 1
TIA
| rex "Return Code (?<returncode>\d+)"
| where isnotnull(returncode) AND returncode!=1
Create an alert based on there being more than 0 results
| rex "Return Code (?<returncode>\d+)"
| where isnotnull(returncode) AND returncode!=1
Create an alert based on there being more than 0 results