@gcusello there is no fields to segregate. Actually, the question is In a Linux machined using JPS command some services is are running, ex: Kafka, JPS etc with PID, if any services are stopped we need to get an alert. Here some tricky idea I have, so if the keyword "Kafka" is not seen in events for more than 1 minute I want to get that alert, so based on this the application team to know oh! the Kafka services are not running in that particulate host. Here is the Query: index="main" host="linux machine" source="logs" "Kafka" Please suggest the query to get the alert when "Kafka" word is seen more than 1 minitue.
... View more