Hi,
I am trying to find the count of total failure to calculate the failure percentage.
OR
In both the cases its always returning 0, whereas I have failure status count is 300 in my logs.
Please help me out in resolving this.
The first stats is correct, provided you have a field named eventtype that occasionally has the value "failure".
As a different approach, try top eventtype instead of stats count.
This will avoid the problem of case-sensitivity:
<yourbasesearch> eventtype="failure" | stats count
And it is probably more efficient. You should try to eliminate as many events as possible in the initial search.
BTW, search
is case-insensitive for values, and that includes field values. But the stats
command and the eval
function are case-sensitive.
The first stats is correct, provided you have a field named eventtype that occasionally has the value "failure".
As a different approach, try top eventtype instead of stats count.
Was just about to post that 🙂
ya, got it the keyword 'Failure' in search is case sensitive.
yes, I have a field in my log with name eventtype which has value failure i.e host=168.94.64.138,eventtype=Failure,facetFieldPrefix="1
Thanks for your reply.