Hello All,
I am trying to build search for common value across multiple host. For example , i have a common field call "eventID" across the multiple host. eventID is dynamic value and keep on changing. How do i build my query so that i can search for host with same eventID.
Also there are other fields, which i want to capture along with host. so final table should be-
eventID host CONNID Time
Try this:
Your Base Search Here | stats first(_time) AS Time values(host) AS host values(CONNID) AS CONNID range(_time) AS duration BY eventID
you can try to do something like ...|stats values(host) by eventID
to get a list of all hosts that have each eventID