HI Team,
I want to get when server goes down time.
time | status |
6/2/2023 12:55 | down |
6/3/2023 12:52 | down |
6/4/2023 12:50 | down |
6/4/2023 12:46 | up |
6/4/2023 12:45 | down |
6/4/2023 12:45 | down |
MY output want to display server down at 12:45
6/4/2023 12:45 | down |
Thanks in Advance..!!
Hi @Anud,
the search depends on your events.
If in each event there's the status field, you could run something like this:
index=your_index
| stats last(status) AS status BY host
| search status="Down"
and schedule this search as an alert.
Ciao.
Giuseppe
Thanks for the response..!!
This one tried giving all down status but i need when down time started first for the server.
Hi gcusello,
I want first down time server status, any idea
time | status |
6/2/2023 12:55 | down |
6/3/2023 12:52 | down |
6/4/2023 12:50 | down |
6/4/2023 12:46 | up |
6/4/2023 12:45 | down |
6/4/2023 12:45 | down |
MY output want to display server down at 12:45
6/4/2023 12:45 | down |