Hey guys,
I have an Error Log table with fields Event ID, Start, End, Duration, Location, Error Code.
How can I filter out events with same Start, End, Location, Error Code but different Event ID?
Thanks a lot!`
| eval DURATION=round(DURATION/60)
| stats count(DURATION) AS "ERROR_QTY" BY 'ERROR CODE'
To keep only one combination of Start, End, Location, Error Code you could do:
| dedup Start End Location "Error Code"
I'm not sure this is what you are asking, though, so if not you may need to add some clarifying details (perhaps sample input and expected output).
Hi Guys,
all good, didn't know I can use dedup for more than 1 fields
Hello @auaave
will you kindly share a sample log for us to better address your question? Thank you.
@ lloydknight, thank you for reply,,, all good now I used dedup for multiple field
To keep only one combination of Start, End, Location, Error Code you could do:
| dedup Start End Location "Error Code"
I'm not sure this is what you are asking, though, so if not you may need to add some clarifying details (perhaps sample input and expected output).