Try like this
index=xyz sourcetype=123 Message ="*" | stats count by host Message | fields - count | appendpipe [|stats count as Message | eval host="Total"]
A little different approach which will print row numbers against each row, but without nested Splunk search query, hence should not cause performance issue.
index=xyz sourcetype=123 Message ="*"
| stat count by host Message
| fields - count
Save as dashboard table and set the table properties to enable Row Numbers. You can do the same by editing Dashboard XML also.
<option name="rowNumbers">true</option>
Hi
Try this search code :
index=xyz sourcetype=123 Message ="*"|stats count by host , Message |fields - count |appendcols[search index=xyz sourcetype=123 Message ="*"|stats count as Total ]
Try like this
index=xyz sourcetype=123 Message ="*" | stats count by host Message | fields - count | appendpipe [|stats count as Message | eval host="Total"]