(index=123) sourcetype=XYZ AND type IN ("SERVICE_STOP") ) | _time host type _raw is the main query where we are searching host where service stop has been observed
Here in this scenario we need to exclude if SERVICE_START event seen with same host within 10 Minutes.
Kindly help me with the query
Thanks in Advance !!
First, search for both SERVICE_STOP and SERVICE_START events. Then use the dedup command to get the most recent event for each host. Filter out the SERVICE_START events and anything that happened in the last 10 minutes. Whatever is left will be a SERVICE_STOP event at least 10 minutes old without a matching SERVICE_START.
index=foo sourcetype=XYZ type IN (SERVICE_START SERVICE_STOP)
| dedup host
| where type=SERVICE_STOP AND _time < relative_time(now(), "-10m")
First, search for both SERVICE_STOP and SERVICE_START events. Then use the dedup command to get the most recent event for each host. Filter out the SERVICE_START events and anything that happened in the last 10 minutes. Whatever is left will be a SERVICE_STOP event at least 10 minutes old without a matching SERVICE_START.
index=foo sourcetype=XYZ type IN (SERVICE_START SERVICE_STOP)
| dedup host
| where type=SERVICE_STOP AND _time < relative_time(now(), "-10m")