Sorry, I am new to Splunk. Now I use a dynamic dropdown to generate all the results, like below:
index=dev-app host=hadoopdn* $importids$ $batchids$ $stages$ |stats count by groupName
Now the query result is like:
FileSystemCounters 10
*.FileType 14
*.StatsCounters 3
*$Counter 6
The problem is the prefix is too long to display.
Is there a way that can only display the latter part?
Like "StatsCounters" instead of "*.StatsCounters"
Maybe use an alias?
... View more