Hello
I have this query:
sourcetype="billinglog" "Reported to MonitorProcessing successfully"| spath "AdditionalData.EventData.MetricName" | search "AdditionalData.EventData.MetricName"=DepositV2 | rename AdditionalData.EventData.monitorProcessingDto.Country as Country | search AdditionalData.EventData.monitorProcessingDto.FTD="*"
| stats count(AdditionalData.EventData.monitorProcessingDto.FTD=Yes) AS FTDyes | table FTDyes
FTDyes returns as 0 while if im changing
AdditionalData.EventData.monitorProcessingDto.FTD="*"
to:
AdditionalData.EventData.monitorProcessingDto.FTD="yes"
i'm getting result 12
what am i missing ?
thanks
Have you tried this (not sure about the case of Yes/yes since you have used it inconsistently)
| stats count(eval(AdditionalData.EventData.monitorProcessingDto.FTD="yes")) AS FTDyes
Yes. it gives the same results