index=perfmonitor sourcetype=dc_perfmonitor source="f:*"
| fields + host, "*Processor Time"
| stats avg("*Processor Time") by host
The output of this query results in a long list of hosts with a staggered table of the average of each machine's average total processor time. I wanted to combine all of these results into a single column.
Basically, I wanted to ask how do I create a new field using this wildcard search (it has a space in its name), as something more general, like "ProcessorTime" vs. "Machine1 Processor Time", "Machine2 Processor Time", "Machine3 Processor Time", etc.?
... View more