The provided search pulls successful purchase events from the online sales data (index=web sourcetype=access_combined action=purchase status=200) and
Question:
The provided search pulls successful purchase events from the online sales data (index=web sourcetype=access_combined action=purchase status=200) and all recorded sales entries from the retail sales data (index=sales sourcetype=vendor_sales.) Calculate the sum of price values from these events, grouped into one-hour increments, and split by index. Run you search over the Last 24 hours. (index=web sourcetype=access_combined action=purchase status=200) OR (index=sales sourcetype=vendor_sales)
Use the where command to only keep events where the web sales values are more than twice as much as retail sales values.
Sort results in descending order based on the web sales values.
Auditing An International Approach
ISBN: 978-0071051415
6th edition
Authors: Wally J. Smieliauskas, Kathryn Bewley