你能帮我下面的..
index=xyz
| eval BlockedStatus =
case(Like(src,"14.19.106.%") AND blocked=1 ,"Q Blocked",
Like(src,"150.29.121.%") AND blocked=1,"Q Blocked",
Like(src,"14.19.106.%") AND blocked=0,"Q Not Blocked",
Like(src,"150.29.121.%") AND blocked=0,"Q Not Blocked",
NOT Like(src,"14.19.106.%") AND blocked=1,"Non Q Blocked",
NOT Like(src,"150.29.121.%") AND blocked=1,"Non Q Blocked",
NOT Like(src,"14.19.106.%") AND blocked=0,"Non Q Not Blocked",
NOT Like(src,"150.29.121.%") AND blocked=0,"Non Q Not Blocked")
| stats count by eventtype BlockedStatus
| rename eventtype as "Local Market", count as "Total Critical Events"
因为我们有 wheresrc=150.29.121.23
和blocked=1
以上查询的数据,所以结果为
"Non Q Blocked" instead of "Q Blocked"
不知道这里出了什么问题