Hi,
I am trying to see if this type of query is possible
I am creating an alert base on 2 conditions.
The first condition must be met and then check the second condition
First Condition: tid result be unique and more than 4 results return
Second Condition: host must be unique and must be more than 1 hosts
Query:
("ERROR")|dedup tid|eval hostname=substr(host,1,5)
It will return something like this
Original host name is
londn1
londn2
eurpn1
eurpn2
The eval will give me
londn and eurpn
I am able to get the first condition working. Once I get the first condition met, I will need to check the result to make sure it comes from more than 1 host (without the 1 and 2 in the hostname).
How should I go about this?
... View more