Hi
Can someone help me with a query please. So I have a field called message which displays the following:
"message":"{\"Status\":\"HEALTHY\",\"Healthy\":[\"PasswordHealthCheck\"],\"Unhealthy\":[],\"Timestamp\":\"2017-07-11T14:08:08\",\"BuildNumber\":\"build-397-deploy-340\"}"
So far my query is like so:
index="css_dev_logs" service=Policebox | spath loggername | search loggername=HealthCheckService
how can I append add to it to say where message \"Healthy\":[\"PasswordHealthCheck\"]
Any help would be greatly appreciated
Thanks
Rob
Try this.
index="css_dev_logs" service=Policebox | spath loggername | search loggername=HealthCheckService | where like(message, "%\"Healthy\":[\"PasswordHealthCheck\"]%")
Try this.
index="css_dev_logs" service=Policebox | spath loggername | search loggername=HealthCheckService | where like(message, "%\"Healthy\":[\"PasswordHealthCheck\"]%")
Thank you Rich