I need to add the hosts to the search below, such as host = "servername"
. It currently brings up all the hosts in the index and I only need a few.
| metadata type=sources index=myindex | join source type=outer [ search index=myindex AND fullload = "]I: Task is running"
| bucket span=1h _time
| stats count by source,
fullload
| eval Date=strftime(_time,"%m/%d/%Y")]| sort + count| fillnull value=0 |where count = 0 |search TaskName = "*_T1"
|fields TaskName, count
you can create lookup of hosts and then filter group of hosts you are looking after