This is a little vague. Are you using this in a dashboard? Or just in the search bar or what? Traditionally you would use the stats
command to get a count of events.
sourcetype=databaseError "object is null" | stats count
But, if you're building a dashboard then you may want the events and the count both on the dashboard. One as a single value field (using | stats count
) and one as a table of events.
Perhaps you could clarify your use for this in order to help folks come up with the best answer?
Hello! Here is what you can do: sourcetype=databaseError|eval object_string=case(searchmatch("object is null"),"object is null")|stats count by object_string
You can take this as an example, with the _internal index:
index=_internal|eval error_tag=case(searchmatch("error"),"error")|stats count by object_tag
Are you looking for something more detailed than the obvious 'stats count'?
sourcetype=databaseError "object is null" | stats count
This is a little vague. Are you using this in a dashboard? Or just in the search bar or what? Traditionally you would use the stats
command to get a count of events.
sourcetype=databaseError "object is null" | stats count
But, if you're building a dashboard then you may want the events and the count both on the dashboard. One as a single value field (using | stats count
) and one as a table of events.
Perhaps you could clarify your use for this in order to help folks come up with the best answer?