I am tracking versions of Operating systems and I'd like to summarize since we have a few different release numbers. Currently I can get a summary with the following simple query :
index=test CURREL=ws* |stats count by ELC_VERSION
This produces a list similar to this:
I'd like to simplify but just having the ELC_VERSION field rolled up into RHEL6 and RHEL7
Try something like this...
index=test CURREL=ws*
| eval ELC = "RHEL".substr(ELC_VERSION,1,1)
| stats count by ELC