Hi,
I want to count the number or errors within two keywords say starttran and endtran.
My log data would be like
My query : sourcetype="abc" | eval haserror=if(searchmatch("error"),1,0) | transaction startswith=starttran endswith=endtran mvlist=haserror | table haserror TRANID
O/P
But i want it like
I tried using sum(haserror) by TRANID but din't. Kindly help . Also here can't TRANID be used as unique ID ?
Thanks a lot
sourcetype="abc"
| eval haserror=if(searchmatch("error"),1,0)
| transaction startswith=starttran endswith=endtran mvlist=haserror
| eval ErrorCount = mvcount(mvfilter(haserror==1))
| table ErrorCount TRANID
should work
sourcetype="abc"
| eval haserror=if(searchmatch("error"),1,0)
| transaction startswith=starttran endswith=endtran mvlist=haserror
| eval ErrorCount = mvcount(mvfilter(haserror==1))
| table ErrorCount TRANID
should work
This worked .. Thanks a lot 🙂