问题描述
你能帮我解决以下问题吗..
index=xyz
| eval BlockedStatus =
case(Like(src,"14.19.106.%") AND blocked=1,"Q Blocked",Like(src,"150.29.121.%") AND blocked=1,"14.19.106.%") AND blocked=0,"Q Not Blocked","150.29.121.%") AND blocked=0,NOT Like(src,"Non Q Blocked","Non Q Not Blocked","Non Q Not Blocked")
| stats count by eventtype BlockedStatus
| rename eventtype as "Local Market",count as "Total Critical Events"
因为我们有src=150.29.121.23
和blocked=1
的数据,但上面的查询给了我结果
"Non Q Blocked" instead of "Q Blocked"
不知道这里出了什么问题