Hi
I want to create a search to find all the events for which last row exists but there is atleast 1 row missing. Example is attached below :
Splunk Query :
`macro_events_prod_gch_comms_esa`
gch_messageType="Seev.047*" host="p*" gch_status="*" NOT"BCS" | table BO_PageNumber,BO_LastPage,gch_status
|rename BO_PageNumber as PageNo , BO_LastPage as LastPage , gch_status as Status
| sort by PageNo
Requirement is find all the events for which LastPage as True exists and there is atleast 1 row missing with PageNo less than the PageNo of row with LastPage as True.
| streamstats count
| where PageNo != count