Hi,
I am doing a search to report on some eventtypes. The eventtypes report fine, but I also want to put anything that isn't categorized as an eventtype into "other" in the table. Is there a way to do this? s
| where isnull(eventtype)
?
Awesome. Thanks. Just took the second reporting class and things are slowly clicking...
Sorry, I thought you wanted to search expressly for items which did not have an assigned eventtype. I suggest yannK's answer above.
source="/var/opt/trapx/log/traps-all.log" | eval eventtype=if(isnull(eventtype),"null",eventtype) | fields eventtype, host |chart count by eventtype, host |addcoltotals | addtotals fieldname=Totals
if the events have no eventtype, then the field will be created and populated with "null"
lost me on that - what is it doing?
My search is:
source="/var/opt/trapx/log/traps-all.log" | fields eventtype, host |chart count by eventtype, host |addcoltotals | addtotals fieldname=Totals
Which works fine, but ignores "non-eventtypes". I want to include totals for these in my chart.