I have a query which results in a table:
"some words" | stats dc(host) as host_count by zone, region
My end goal is be able to create an alert if "host_count < 2" in any row. I will achieve that by adding " | where host_count < 2" to the query and alerting if the search is non-empty.
The issue is that in some cases, when there are no lines matching the "some words" criteria, I will have no row for that zone/region combination in my table. (i.e. I will never have a row where host_count is 0). This will result in a false negative for the alert.
I had the thought that I could possibly merge the search result with a lookup table which provides the 0 value lines, but had no success.
How can I achieve this?
... View more