Hi there,
I want to know if this is possible:
I have a simple search:
index=myindex host=myhost* | stats count by host
which returns
myhost1->10
myhost2->20
myhost3->30
myhost-new1->100
myhost-new2->200
myhost-new3->300
Now, is it possible to aggregate the counts further by the host type? Which should return
old-hosts->60
new-hosts->600
Thanks!
Try this
index=myindex host=myhost* | eval age=if(match(host, "new"), "new-host", "old-host") | stats count by age
Try this
index=myindex host=myhost* | eval age=if(match(host, "new"), "new-host", "old-host") | stats count by age