Hi,
It seems I cannot get any search results without including a wildcard in messagetype.
More specifically:
After searching for messagetype="proposal"
, no events are shown.
Searching for messagetype="*proposal"
, events are shown.
Further research also showed that there aren't any special characters involved in the problem.
This is the complete query:
index="*-closecl-*" application="closecl" component="closecl-bfl-ws"
environment=*
transactionType="notifyParty" messageType="*proposal" | dedup TranID sortby +_time| lookup CloseCLDossierMetaData uid as TranID OUTPUTNEW uid CustomerCode, ProductType, GrossCreditAmount, LabelCode, ProductCode, SourceSystem | timechart minspan=1d bins=60 dc(TranID) as count | fillnull
Thanks in advance!
updated by dmj to mark code
index="-closecl-" application="closecl" component="closecl-bfl-ws" environment=* transactionType="notifyParty" messageType="proposal" | eval messageType=trim(messageType) | rest of your query
@sbbadri - be sure to mark your code, please.
Run this and post the results, please...
index="*-closecl-*" application="closecl" component="closecl-bfl-ws" environment=*
transactionType="notifyParty" messageType="*proposal"
| eval myproposal="---".messageType."---"
| stats count by myproposal
Can you share some sample data?