Here is my complete search: | from datamodel:"dataset_backup_job_events"| where clusterName=="ITSEDC07-SD02A" | where eventStatus=="Failure" | table _time,objectName,message,locationName,eventStatus,objectType,objectId,_raw | eval json_field=split(_raw,",") | eval field1=mvindex(json_field,1) | eval field1=replace(field1,"\"","") | eval field2=mvindex(json_field,2) | eval field2=replace(field2,"\"","") | eval field3=mvindex(json_field,3) | eval field3=replace(field3,"\"","") | eval field4=mvindex(json_field,4) | eval field4=replace(field4,"\"","") | eval field5=mvindex(json_field,5) | eval field5=replace(field5,"\"","") | eval field6=mvindex(json_field,6) | eval field6=replace(field6,"\"","") | eval field7=mvindex(json_field,7) | eval field7=replace(field7,"\"","") | eval field8=mvindex(json_field,8) | eval field8=replace(field8,"\"","") | eval field8=rtrim(field8,"}") | eval human_readable_time=strftime(_time, "%Y-%d-%m %H:%M") | eval itsi_entity=objectName, itsi_event_key=objectId, itsi_correlation_key=objectId, itsi_summary="Backup "+eventStatus+" for "+objectName, message=message, itsi_tag=mvappend("NowIT", "ITSI"), itsi_message="Alerting time: "+human_readable_time+"~~"+field1+"~~"+field2+"~~"+field3+"~~"+field4+"~~"+field5+"~~"+field6+"~~"+field7+"~~"+field8, itsi_impact=case( message like("%Failed log backup of Oracle Database%") ,"High", message like("%Failed backup of Oracle Database%"),"High", true(), "Medium"), itsi_urgency=case( message like("%Failed log backup of Oracle Database%"), "High", message like("%Failed backup of Oracle Database%"), "High", true(), "Medium") | rex mode=sed field=itsi_message "s/\\\/-/g"
... View more