I have the following search, and i want to be able to only show the indexes that have 0 data during a specified time frame.
index=_internal source=*license_usage.log type="Usage" | timechart count by idx span=1h
When I add
| where count=0 or something similar it shows nothing.
Any example searches to show indexes that have no data and be able to set up an alert when that happens?
try this :
| eventcount summarize=false index=* | dedup index | fields index | rename index as idx | join type=left idx [ search index=_internal source=*license_usage.log type="Usage" | bin span=1d _time | eval time=strftime(_time,"%Y-%d-%m") | chart count over idx by time ]
let me know if this helps !