我有消息过滤器
fields @timestamp, @message
| sort @timestamp desc
| filter @message ~= 'simple query'
| limit 20
我应该使用什么查询来搜索带有消息的结果:
simple query
simple query 1
simple query 2
simple query error
simple query etc...
大thx!
有两个选项是strcontains
和like
方法:
strcontains:
fields @timestamp, @message
| filter strcontains(@message, "simple query")
| sort @timestamp desc
| limit 20
类似:
fields @timestamp, @message
| filter @message like /simple query/
| sort @timestamp desc
| limit 20