Hi,
I need help with below query search. Below is the sample logs.
Logs:
Conatainer: dev_test_cluster
CountRequired: 2
CountRunning: 1
FunctionName: dev_dd_app
I need to write a query for to compare the CountRequired and CountRunning values and show details when CountRunning is less than CountRequired.
Appreciate the help.
Hi @rajs115
Does something like this work for you:
index=<your index> sourcetype=<your sourcetype>
| eval RunningLessThanRequired = if(CountRunning < CountRequired, 1, 0)
| where RunningLessThanRequired = 1
Thanks Jamie. It worked
Hi @rajs115
Does something like this work for you:
index=<your index> sourcetype=<your sourcetype>
| eval RunningLessThanRequired = if(CountRunning < CountRequired, 1, 0)
| where RunningLessThanRequired = 1