I appreciate the quick reponse @richgalloway but this query fails in scenario where: COMPLETED (C) Event1, Event2, Event3 and IN-PROGRESS (I-P) Event1, Event2, Event2, Event2 Then index=abc (message="*IN-PROGRESS*" OR message="*COMPLETED*")
| eval splitStr=split(message, ",")
| eval eventName=mvindex(splitStr,1) This query will list Event1(C), Event1(I-P), Event2(I-P),Event2(I-P),Event2(I-P),Event2(C),Event3(C) and | dedup eventName will return Event1(C), Event2(I-P),Event3(C) and | where NOT match(message, "COMPLETED") will return Event2 Ideally, result should be 0. Thank you.
... View more