HI,
I have a search in which I am interested in three fields:
index=my_computer sorucetype=asia_data message="Null_fields" | table item_id, country, count
My data has the same item id for multiple countries, say : Item1 for CHN,JPN. IND etc.
Also, it can occur multiple times for the same country.
There could be multiple hosts for the same country.
SO I want results in the format
ITEM_ID Countries HOST
Item1 CHN, JPN Host1, host2
I tried using mvcombine, but it does not give the result as per my expectation.
If I understand correctly your question:
index=my_computer sorucetype=asia_data message="Null_fields"
| stats values(country) as Countries, values(host) as host by item_id