Today I am lack of knowledge... I have to build an availability report of a specific service on multiple servers. My Events look like as follows:
starttime, endtime, errorcode, servicename, servername
I would like to have a search result only when the error occurs on 4 servers at the same time.
I am confused how I can correlate the servername. My first try was
| where servername=server1 OR servername=server2.....
but this does not work... but concatenating with AND does not work neither....
Thank you guys, sorry for my foolery