I am trying to run a query that will return the total message count for the field PStream for any of the possible values. For example there are over 100 different PStream values, and I am setting up an alert system that will trigger an alert when the count = 0 for the last hour for any of the PStream values. Could someone assist or suggest a way to construct this query? Would really appreciate it.
You could use a boolean query with a must_not clause which contains the missing query to query for all messages where PStream has a value (i.e. where the value is not missing).
Thanks for the responses and suggestion. I apologize, I should have been a little more clearer. I am mainly worried about the counts of that value and not missing values as that field will always be occupied and will serve as the identifier.
this is more like what I need. I need to get the counts for all messages with PStream: * and if count = 0, then that creates an alert. The only thing I don't have correct yet, is defining a time window. Tried to add the following but getting parser error:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.