Hi All,
Need to get the host count with splunk_server names by using the search queries, i have used below but its giving the all the events
index=main sourcetype="WinEventLog:Security" host=* splunk_server=*
Thanks
Try this
index=main sourcetype="WinEventLog:Security" | stats count(host) by splunk_server