First query index = pcf_logs cf_org_name = creorg OR cf_org_name = SvcITDnFAppsOrg cf_app_name=VerifyReviewConsumerService host="*" | eval _raw = msg | rex "Request\#\:\s*(?<ID1>\d+) with (?<Status>\w+.\w+)"|rex "CRERequestId\"\:\"(?<ID2>[^\"]+)" | eval ID=coalesce(ID1,ID2) | stats latest(Status) as Status by ID | eval Status=trim(Status, "status ") | stats count by Status Second query index = pcf_logs cf_org_name = creorg OR cf_org_name = SvcITDnFAppsOrg cf_app_name=VerifyReviewConsumerService host="*" | search msg="*Rejected*" | eval _raw = msg | rex "(?<CRE_Creation_Date>\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}\s..)" | rex "Request\#\:\s*(?<Rejected_CRE_ID>\d+)" | rex status(?<Rejected>\s\w+) | rex (?<Failed_Reason>Rule.*)$ | eval Failed_Reason=trim(Failed_Reason, "Rule ") | stats count by CRE_Creation_Date Rejected_CRE_ID Rejected Failed_Reason
... View more