Hi All,
I am trying to add severity column to output of first command, could you please let me know how to do it.
Query I have created is :
index=abc source=xyz | table _time ID STATUS ERROR_Name | search ERROR_Name IN ("EndDate must be after StartDate""The following is required: PersonName" ....many others) | join type=inner ID[search index=abc source=xyz STATUS IN (FATAL,SUCCESS) | table _time ID STATUS | stats latest(STATUS) as STATUS by ID | search STATUS IN (FATAL) | fields ID] | stats latest(STATUS) as STATUS by ID ERROR_Name | search STATUS IN (FATAL) | top 50 ERROR_Name | appendcols [| eval severity = case(ERROR_Name=="EndDate must be after StartDate", "One", ERROR_Name=="The following is required: PersonName", "two")]
... View more