Hi @aditsss , you have to use a common key to group events: search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event bal...
See more...
Hi @aditsss , you have to use a common key to group events: search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")|head 7
| eval
EBNCStatus="ebnc event balanced successfully",
StartTime=strptime(StartTime,"%Y-%m-%d %H:%M:%S.%3N"),
EndTime=strptime(EndTime,"%Y-%m-%d %H:%M:%S.%3N")
| rename
busDt as Business_Date
fileName as File_Name
CARS.UNB_Duration as CARS.UNB_Duration(Minutes)
| stats
earliest(StartTime) AS StartTime
latest(EndTime) AS EndTime
values("CARS.UNB_Duration(Minutes)") AS "CARS.UNB_Duration(Minutes)"
values(Records) AS Records
values(totalClosingBal) AS totalClosingBal
values(totalRecordsWritten) AS totalRecordsWritten
values(totalRecords) AS totalRecords
values(EBNCStatus) AS EBNCStatus
BY Business_Date File_Name
| eval
StartTime=strftime(StartTime,"%Y-%m-%d %H:%M:%S.%3N"),
EndTime=strftime(EndTime,"%Y-%m-%d %H:%M:%S.%3N")
| sort -Business_Date if you have more values for the other fields, you can use other functions as last or first. Ciao. Giuseppe