Hello, I have a lookup where all the hostnames are available under the field called "title" with respect to teams.I would like to set up an alert for team "abc" if any of the host stops reporting for more than 15 mins, I tried the below search but unable to get the results.Can anyone please help me with the search, it is highly helpful. Search which i am using: | inputlookup 123.csv | search team="abc" | table title | rename title as host | appendpipe [ | stats count as islookupcount ] | eval current_time =now() | eval islookupcount = coalesce(islookupcount, 0) | search islookupcount = 0 | eventstats latest(_time) as last_event_time by host | where current_time - last_event_time > 900 | eval stopped_sending_time=strftime(current_time,"%Y-%m-%d %H:%M:%S") | table unit_id, host, stopped_sending_time please help me with the better search for my usecase may be i am not using the right one. Thanks
... View more