hI
I use the request below
sometimes I have only value for Free_Space and sometimes only value for TotalSpace instead both
I need a way to don't dispalay the result (in table) if one of these 2 fields is NULL
Could you help ME please??
(eventtype="TotalSpace" OR ( eventtype="DiskHealthSize" AND Value<15))
| eval time = strftime(_time, "%m/%d/%Y %H:%M")
| eval Value = round(Value, 1). " %"
| eval TotalSpace = TotalSpaceKB/1024
| eval TotalSpace = round(TotalSpace/1024,1). " GB"
| stats latest(Value) as Free_Space latest(TotalSpace) as TotalSpace by host
| sort +Free_Space limit=10
Thanks
Hi @jip31
Try like
your query...
|search Value=* AND TotalSpace=*
| stats latest(Value) as Free_Space latest(TotalSpace) as TotalSpace by host
| sort +Free_Space limit=10
can you share your events ?
Hi
Thanks but i am not sure that * is the better day? I try with fillnull but i dont succeed
Or try with |where Value !="" AND TotalSpace !=""
or |where isnotnull(Value ) AND isnotnull(TotalSpace )
yes many thanks
@jip31 have you tried?
Hi @jip31
Try like
your query...
|search Value=* AND TotalSpace=*
| stats latest(Value) as Free_Space latest(TotalSpace) as TotalSpace by host
| sort +Free_Space limit=10