Hi,
I want the alert to trigger if there are extracts where TOTAL_PIECES >0 and RETRIEVAL_ATTEMPT= 10
Is there anybody can help with this please?
My search is,
index=A source=B sourcetype=c
| fillnull value=0 TOTAL_PIECES RETRIEVAL_ATTEMPT
| where RETRIEVAL_ATTEMPT= 10
| rename "SASP_CTRL_SEQ_NBR" as "Extract_Seq_ID" ,"IV_STS" as "IV_Status", "RETRIEVAL_ATTEMPT" as "Retrieval_Attempt","PSTG_STMT_N" as "Pos_St","TOTAL_PIECES" as "Piece_Count"
| table "Extract_Seq_ID","IV_Status","Retrieval_Attempt","Pos_St","Piece_Count"
... View more