Hello all, Thank you for your help. I finally found the solution by doing that and optimizing the result by adding some more filters like severity: index=my_index sourcetype=alerts (eid=* AND result="1" AND severity>2 AND error=*) OR (init_eid=* AND result="0")
|fields result,init_eid,eid,Host,severity,error
|eval Merged_eid=coalesce(init_eid,eid)
|eval resolved=if(isnull(init_eid),"No","Yes")
|stats max(Host) as Host min(_time) as _time max(error) as Alert max(resolved) as Resolved max(severity) as Severity by Merged_eid
|search Severity>2 AND Resolved="No" Have a great day.
... View more