Hi
Please help me a little "Search Command".
In accesslog, I should need two results.(count)
I Have a field name "status".
Using status field under line.
--- result ----
* | 404 | 40x 50x | ~
6 300 ===> count
Please help me.
Thanks
Hi Ayn!
Thank you for answer.
I learned so much thanks.
Awesome. Could you please mark my answer as accepted? Thanks!
I'm GUESSING the question is how you can get a table containing a count of the different values for the field "status"?
... | stats count by status
Or is the issue how to have one count for "404", but then group together all other 40x status codes? In that case use eval
:
.... | eval status_group=case(status="404","404",match(status,"^40"),"40x",match(status,"^50"),"50x") | stats count by status_group