I have the following scenario where duplicate accounts has been created for a transaction id value. I would like to count how many duplicates has been created and list it as a table. I compare the message with a string, which indicates the successful creation of the account. The current query is as follows:
index=myindex sourcetype=mysourcetype | spath message | search message="Account Created Successfully" |stats count by transactionId
I have the following format for logs
message: Account Created Successfully
The above search query is not giving me the correct counts. I manually checked the logs for the transaction ID, but the `stats` count is wrong. How can I modify the query to get accurate counts ?