I need to return a "yes"
if (host=A has events > 0 and host=B has events > 0)
else '"no"
sundareshr,
Won't that search give either host=A or host=B (...or maybe both) ? I need to return a "yes' when I have failure record from BOTH host=A and host=B
Try this
index=yourindex host=A OR host=B "failure" | stats count | eval result=if(count>0, "Yes", "No")
Won't that return a "yes" if either host A or host B returns an event?
I need when both host a and host b return an event
Ah!!! Try this
index=yourindex host=A OR host=B "failure" | stats dc(host) as hosts | eval result=if(hosts=2, "Yes", "No")
Yes I believe that will do it, you da man...Is there a way to pass the value of 'result' to a windows batchfile
that will be triggered to run when this alert runs?