Time Event 4/27/245:30:37.182 AM { "Client":"ClientA", "Msgtype":"WebService", "Priority":2, "Interactionid":"1DD6AA27-6517-4D62-84C1-C58CA124516C", "Seq":15831, "Threadid":23, "message":"TimeMarker: MyClient: Result=Success Time=0000.05s Message=No payments found. (RetrievePaymentsXY - ID1:123131 ID2:Site|12313 ID3:05/14/2024-07/12/2024 1|12313", "Userid":"Unknown" } I just want to make sure that I state it right, when I run the following query, I get an output already, so json and fields are all correct. It is just my json was messed up when I massaged it (please ignore) : index=application_na
sourcetype=my_logs:hec
source=my_Logger_PROD
retrievePayments*
returncode=Error
| rex field=message "Message=.* \((?<apiName>\w+?) -"
| lookup My_Client_Mapping Client OUTPUT ClientID ClientName Region
| chart count over ClientName by apiName where `chart count over` is at the end. But, when I move the `lookup` statement after `chart`, I don't get any data back. If I remove the `lookup` the query won't work as `ClientName` is stored in lookup mapping file.
... View more