HI Team,
I want to get when server goes down time.
| time | status |
| 6/2/2023 12:55 | down |
| 6/3/2023 12:52 | down |
| 6/4/2023 12:50 | down |
| 6/4/2023 12:46 | up |
| 6/4/2023 12:45 | down |
| 6/4/2023 12:45 | down |
MY output want to display server down at 12:45
| 6/4/2023 12:45 | down |
Thanks in Advance..!!
Hi @Anud,
the search depends on your events.
If in each event there's the status field, you could run something like this:
index=your_index
| stats last(status) AS status BY host
| search status="Down"and schedule this search as an alert.
Ciao.
Giuseppe
Thanks for the response..!!
This one tried giving all down status but i need when down time started first for the server.
Hi gcusello,
I want first down time server status, any idea
| time | status |
| 6/2/2023 12:55 | down |
| 6/3/2023 12:52 | down |
| 6/4/2023 12:50 | down |
| 6/4/2023 12:46 | up |
| 6/4/2023 12:45 | down |
| 6/4/2023 12:45 | down |
MY output want to display server down at 12:45
| 6/4/2023 12:45 | down |