Hello,
I would like to Check for each host, its sourcetype and count by Sourcetype.
I tried host=* | stats count by host, sourcetype
But in fact I need all the sourcetypes to be set as column, and get the count by host for each sourcetype. Can you help ?
Many thanks
Hi @warmup031,
did you tried?
index=your_index
| stats count by sourcetype host
host=* isn't needed because all the events has the field host and use always the index in main search.
Ciao.
Giuseppe
Hello gcusello and adonio, I already tried thèse search but my main problem is to set each sourcetype as a column, hosts as row and get sourcetype count valid for each host
Thank you
Hi @warmup031,
did you tried?
index=your_index
| stats count by sourcetype host
host=* isn't needed because all the events has the field host and use always the index in main search.
Ciao.
Giuseppe
Hi @warmup031,
please, try this
index=wineventlog
| chart count OVER host BY sourcetype
Ciao.
Giuseppe
Wonderful, thank you very much Giuseppe
You're welcome!
Ciao and Next time.
Giuseppe
try this:
| tstats count as event_count where index=* by host sourcetype