Hello!
I have events from two different fields that are correlate each other by the time.
So I want to make a table extracting only those values that were generate at the same time from a range of time of one day.
For example in the table below, there are two values that has the same time:
How can I extract the events that only has the same timestamp from those two fields (MSGNUM=SVM4000I and SVM4874I)
@danielgp89,
Try this and verify if its working for you
"your base search"|eventstats dc(MSGNUM) as c by _time|where c>1
This should result only those events which has at least 2 MSGNUM values of same time
@danielgp89,
Try this and verify if its working for you
"your base search"|eventstats dc(MSGNUM) as c by _time|where c>1
This should result only those events which has at least 2 MSGNUM values of same time
Thanks so much Renjith!
Your going to heaven!