Hello all, I am facing an issue in appending an query. Here my objective is to update the kv store with the list of servers, alert_flag(if the alert has been raised) and count(number of times the server has created an event). Below is the query that I have used. index= index | lookup source_host_kvstore_001 source_host OUTPUT source_host as temp_source_host count alert_flag| dedup source_host | eval count=if(isnull(count),0,count)| eval count = count+1 | eval alert_flag = if(isnull(alert_flag),0,if((alert_flag=1),1,0)) | eval _time=now() | table _time source_host alert_flag count | sort -_time | outputlookup source_host_kvstore_001 append=true When the above is ran everytime the same host is updated and also added in the new row, however, I need a single update of the count and alert_flag for a host. The data is pushed to the kv store as below by a new increase in the count. _time alert_flag count source_host 2021-03-05 13:01:50 0 1 Server 1 2021-03-05 13:01:50 0 1 Server 2 2021-03-05 13:01:50 0 1 Server 3 2021-03-05 13:01:53 0 2 Server 1 2021-03-05 13:01:53 0 2 Server 2 2021-03-05 13:01:53 0 2 Server 3 However, I am looking for the data to be updated in the KV store like below. _time alert_flag count source_host 2021-03-05 13:01:53 0 2 Server 1 2021-03-05 13:01:53 0 2 Server 2 2021-03-05 13:01:53 0 2 Server 3 Please guide me through this. Regards
... View more