Hi Guys,
my question is Can priority (the regular P1/P2/P3 column) and job alias from the pw_map lookup be added to this alert as additional columns? I’ve recently started seeing some ingest issues with a few queues, and these columns would help with escalation and determining downstream impacts.
Hi @majilan1,
if the fields to add (priority and job) are fields of the lookup you're using, you can add them to your results adding a values option for each of them to the stats command, something like this:
| stats latest(curdepth) as curdepth first(curdepth) as firstCur count as event_count sum(over_threshold) values(priority) AS Priority values(job) AS Job
Ciao.
Giuseppe