In my table, I have a field named Username, and it has two values: Machine 1 and 2. I only want to show Machine1 only without showing Machine2. How would I do this? thanks!
Add | search Username=Machine1
to your query.
Like this:
... | eval Username = mvindex(Username, 0)
I did this but it still shows both machine 1 and 2
@mdmaala,
Is it a multi value field or delimiter(comma,space,etc) separated? Can you share some sample events of the field?
Add | search Username=Machine1
to your query.
I did this and this works! but in my graph it still leaves a gap for machine 2 values for every timestamp registered, is there anyway that I can remove that in the graph and show the values for machine 1 only?
thanks! I was able to search only for Machine1 values. but in my graph it still leaves a space for machine 2. I only want to graph values for machine 1