Try using stats.
index=foo
| stats values(*) as * by id
| where isnull(mvfind(event, "batch_send_success"))
The stats command combines all "event" fields with the same id. Then mvfind is used to find those that don't contain (returns NULL) "batch_send_success".
Try using stats.
index=foo
| stats values(*) as * by id
| where isnull(mvfind(event, "batch_send_success"))
The stats command combines all "event" fields with the same id. Then mvfind is used to find those that don't contain (returns NULL) "batch_send_success".