I have a log entry that will display:
Processor being destroyed
And when it does (within my real-time search (all time)), I want to display Yes (Green) in a dashboard panel.
When it has not yet occurred, I want the dashboard panel to display No (Red).
If yes/no is not possible and True/False is, then that is ok too. 🙂
The above app does work for 6.2.
If you just want to display Yes/No for value in the single value panel, you can have your search like this (sample)
your base search "Processor being destroyed" | head 1 | stats count | eval result=if(count=1,"True","False") | table result