Hi @parthiban , you have only to setup the conditions for the alert: <your_search>
| stats
count(eval(status="offline")) AS offline_count
count(eval(status="online")) AS online_count
earl...
See more...
Hi @parthiban , you have only to setup the conditions for the alert: <your_search>
| stats
count(eval(status="offline")) AS offline_count
count(eval(status="online")) AS online_count
earliest(eval(if(status="offline",_time,""))) AS offline
earliest(eval(if(status="online",_time,""))) AS online
| fillnull value=0 offline_count
| fillnull value=0 online_count
| eval condition=case(
offline_count=0 AND online_count>0,"Online",
offline_count>0 AND online_count=0,"Offline",
offline_count>0 AND online_count>0 AND online>offline, "Offline but newly online"),
offline_count>0 AND online_count>0 AND online>offline, "Offline"),
offline_count=0 AND online_count=0, "No data")
| search condition="Offline" OR condition="Offline but newly online"
| table condition in this way your alert will trigger the two conditions. Ciao. Giuseppe