Hi Experts!
I'm looking for a way to show where i get bookingresponses with the SAME (duplicate) platformid but different reactorids.
Example:
2019/02/03 12:02:14.458 [server1] event="Received booking response" platformid=12345 reactorid=72E1X9785
2019/02/04 18:02:14.458 [server2] event="Received booking response" platformid=12345 reactorid=92D3X1865
I tried a mix of using dedup and transaction, but I can't seem to filter on having what i want left.
Thanks in advance,
Paul
What about just this: YOUR SEARCH| stats dc(reactorid) as distinct values(reactorid) as reactorids by platformid | search distinct > 1
Like this:
... | stats values(reactorid) AS reactorids dc(reactorid) AS reactoridCount range(_time) AS duration BY platformid
| where reactoridCount > 1 AND duration = 0
What about just this: YOUR SEARCH| stats dc(reactorid) as distinct values(reactorid) as reactorids by platformid | search distinct > 1
Great Thanks for this guys