Following query with Transaction without endswith
host=phenix ("Scheduler started" OR "Scheduler stopped" OR "Restarting Protocol" OR "Stopping Protocol" OR "Protocol complete. Process") | transaction date_month date_mday startswith=("Restarting" OR "started")| stats sum(duration) AS dur by date_mday date_month| eval durInHr=dur/3600
date_mday ____________ date_month ________________ dur ____________ durInHr
When added endswith option:
host=phenix ("Scheduler started" OR "Scheduler stopped" OR "Restarting Protocol" OR "Stopping Protocol" OR "Protocol complete. Process") endswith="stopped" | transaction date_month date_mday startswith=("Restarting" OR "started")| stats sum(duration) AS dur by date_mday date_month| eval durInHr=dur/3600
date_mday ____________ date_month ________________ dur ____________ durInHr
I was hoping to get smaller duration using endswith, which is not the case here.
Looks like I found the answer. There are events with few repetitive keywords
Restarting
Restarting
stopped
Restarting
stopped
stopped
Looks like I found the answer. There are events with few repetitive keywords
Restarting
Restarting
stopped
Restarting
stopped
stopped