Many people ask questions here that are tricky enough that the only way to get an answer that works is to play around with the data quite a bit. In order to do this, we have to fake data first. For the following data set, what is the best way to do it?
host source count name
host1 sourceA 33 Inky
host2 sourceA 23 Pinky
host3 sourceB -2 Blinky
host4 5 Clyde
What about for multi-value
fields?
The best way is like this:
| makeresults | eval _raw="
host source count name
host1 sourceA 33 Inky
host2 sourceA 23 Pinky
host3 sourceB -2 Blinky
host4 5 Clyde"
| multikv forceheader=1