I have the following command:
sourcetype="sourcetype" eventid=731 OR eventid=730
| stats latest(eventid) by target
| chart count by eventid
the 2nd line works as expected, but when I add in the 3rd line, i get "No results found"
I want to display the results of the 2nd line in a pie chart rather than a table.
Hi
add AS eventid
to your stats command
sourcetype="sourcetype" eventid=731 OR eventid=730
| stats latest(eventid) AS eventId by target
| chart count by eventid
Bye.
Giuseppe
@jared_anderson, following should also give you same result. Dedup will get latest events for each target which enables you to count latest eventid for unique targets.
sourcetype="sourcetype" eventid=731 OR eventid=730
| dedup target
| chart count by eventid
Hi
add AS eventid
to your stats command
sourcetype="sourcetype" eventid=731 OR eventid=730
| stats latest(eventid) AS eventId by target
| chart count by eventid
Bye.
Giuseppe
why is the AS eventid needed?
Because if you don't use it, the stats result field name is latest(eventId) as you can see in the column header running Your first two tows.
Bye.
Giuseppe