Hello
I use the search below :
[| inputlookup host.csv
| table host] index="x" sourcetype="PerfmonMk:Process" process_name=chrome ("%_Processor_Time"=0)
| lookup lookup_cmdb_fo_all.csv HOSTNAME as host output SITE
| search SITE=$tok_filtersite|s$
| stats count(process_name) as Total by host
| sort -Total limit=10
I need to display host, SITE and Total fields
I m doing
| table host SITE Total
But SITE doenst display
What I have to do please?
Hi,
When you use stats
in your query it will drop remaining fields. So try this | stats count(process_name) as Total, values(SITE) as SITE by host
Hi,
When you use stats
in your query it will drop remaining fields. So try this | stats count(process_name) as Total, values(SITE) as SITE by host
Oh many thanks