Incident=113 Group=ABC Status = Open
- Incident=113 Group=XYZ Status = Closed
Incident=114 Group=ABC Status = Open
- Incident=114 Group=ABC Status = Closed
Incident=115 Group=ABC Status = Open
Incident=116 Group=ABC Status = Open
- Incident=116 Group=XYZ Status = Closed
I want write a query to get only those Incidents which are currently opened with group ABC. The result should NOT have : 114 As it was closed by ABC group. The result should NOT have : 113 and 116 As they were eventually closed by some other group.
My result should be :
112 and 115
index=test sourcetype=test_st | search group="ABC" AND status="Open"