Each host has a particular keyword (they are extracted by field extractor), some hosts share the same keywords.
I am trying to count the number of hosts per keywords. i.e.
keyword1, - Number of times it Appears in hosts
keyword2, - Number of times it Appears in hosts
I am doing this but it is giving me a very high count
index=main host="*"
| search * keyword!="NULL"
| stats count(host) as host_numbers by keyword
What you need is distinct_count. Try this
index=main host=""
| search keyword!="NULL"
| stats dc(host) as host_numbers by keyword
What you need is distinct_count. Try this
index=main host=""
| search keyword!="NULL"
| stats dc(host) as host_numbers by keyword