I have log as below:
{"Timestamp":"2019-03-12T16:25:11.4287941+00:00","Level":"Fatal","MessageTemplate":"{Level}: {Event} - Additional Data:{@Data}","Exception":"XYZ: Sync Queue Max Limit Reached","Properties":{"Level":"Fatal","Event":"MaxSyncLimit","Data":{"Node":"LVSP10SYS005","TaskCount":20},"MachineName":"ABC","ExceptionDetail":{"Message":"Sync Queue Max Limit Reached","Data":{},"InnerException":null,"TargetSite":null,"StackTrace":null,"HelpLink":null,"Source":null,"HResult":-2146233088,"Type":"XYZ"},"LogType":"Admin","Application":"SyncNode","Environment":"V3"}}
Hi @ychichani,
Have you tried:
|eval TaskCount='Properties.Data.TaskCount'
Hi @ychichani,
Have you tried:
|eval TaskCount='Properties.Data.TaskCount'
index=applogs Level=Fatal "Properties.Event"=MaxSyncLimit "Properties.ExceptionDetail.Message"="Sync Queue Max Limit Reached"
| eval TaskCount = "Properties.Data.TaskCount"
| search TaskCount > 20
| stats count by "Properties.Data.TaskCount", host
Thanks
But it also returning events lesser than 20
Your welcome!