Hi
I have fields created for both sessionId and host. Now I wanna find out the same sessionId happening in two different hosts and list them:
search: index="atg" sessionId="*mob" host="*"
sessionId example =16E4E8BA9480F388B11B3FC35B07732E.svcldprdapp06b-33mob
Try something like this
index="atg" sessionId="*mob" host="*" | stats dc(host) as hostCount values(host) as hosts by sessionId | where hostCount>=2
What if I want to plot it on a graph on timechart like how many sessionIds had more than 1 hosts over a specific period of time
Try something like this
index="atg" sessionId="*mob" host="*" | stats dc(host) as hostCount values(host) as hosts by sessionId | where hostCount>=2
Thanks worked great