Hello,
I am currently faced with the problem while creating stats for a specific event, where the event itself contains a custom source field. With my current search it will use the default source field rather than the custom source field of the event. How can I use this custom source field in the by clause of the stats command?
Here an event sample:
name=testEvent source=application1 eventType=type1
Here the search:
eventType=type1 | stats count as occurrences by source, eventType
Thanks in advance,
Rainer
This is a little clunky but it will work
eventType=type1 | rex "source=(?<Source>\S+)" | stats count as occurrences by Source, eventType
Notice that your custom source is now named "Source". Since field names are case-sensitive, this avoids the conflict.
You could put this regular expression into the appropriate props.conf
file and then your "Source" would always be accessible, without the need for the rex
command...
This is a little clunky but it will work
eventType=type1 | rex "source=(?<Source>\S+)" | stats count as occurrences by Source, eventType
Notice that your custom source is now named "Source". Since field names are case-sensitive, this avoids the conflict.
You could put this regular expression into the appropriate props.conf
file and then your "Source" would always be accessible, without the need for the rex
command...
thank you!