If I search by using below SPL index=prod_solarwinds (source="rest://Prod_Solarwinds_Agent_Asset" OR source="rest://Prod_Solarwinds_ICMP_Asset" ) Caption=FREQSAPP150 |search Vendor="*" Caption="*" |search * Vendor="*" |dedup _time |table _time Caption ResponseTime Status | replace *-primary WITH * IN Caption | replace *-secondary WITH * IN Caption |eval Availablity = if(ResponseTime < 0 AND Status=2,0,1) |sort Caption _time limit=0 |dedup _time Caption I get 2760 records while using index=prod_solarwinds (source="rest://Prod_Solarwinds_Agent_Asset" OR source="rest://Prod_Solarwinds_ICMP_Asset" ) |search Vendor="*" Caption="*" |search * Vendor="*" |dedup _time |table _time Caption ResponseTime Status | replace *-primary WITH * IN Caption | replace *-secondary WITH * IN Caption | search Caption=FREQSAPP150 |eval Availablity = if(ResponseTime < 0 AND Status=2,0,1) |sort Caption _time limit=0 |dedup _time Caption I get only 3 as below Complete 5,889 events (1/1/23 12:00:00.000 AM to 2/1/23 12:00:00.000 AM) time Caption ResponseTime Status Availablity 2023-01-29 15:00:47 FREQSAPP150 -1 2 0 2023-01-29 16:52:51 FREQSAPP150 -1 2 0 2023-01-31 19:06:59 FREQSAPP150 -1 2 0 problem is here due to this Availaibility from search is coming around 80% and from second its coming 0, i want understand why its happening
... View more