I am running the following query , which is returning the number of events where "failures" keyword is occuring , but how can I find how many times "failures" keyword occured in each event
index=abc "failures"|stats count by host|eventstats sum(count) as totalCount
Hey Navd,
based on the scenario this search might work.
Do let me know if this is helping you.
index=abc sourcetype=xyz "failures"| rex max_match=0 "(?P<term>failures)"
| eval count=mvcount(term)
| stats sum(count) as Total by term
You can do this by extracting all occurrences of the string "failures" to a field and then count all instances of that field:
index=abc "failures" | rex max_match=0 "(?<failures>failures)" | stats count(failures)