Hi
I use the scheduled search below
eventtype="AppliService" Name="mfevtp"
| fields Name, host
| dedup host Name
| stats count
This search is called from the dashboard with a loadjob command
| loadjob savedsearch="admin:xx:xx"
**| search host=$tok_filterhost$**
| fields - host
| append
[ makeresults
| eval EventCode=0]
| stats sum(EventCode)
But I have an issue with | search host=$tok_filterhost$
When I delete this piece of code I have results.
When there is this one, I have a 0 result even if I put a host name in my token entry.
It's strange because I have already used this kind of search, and it was working perfectly.
Is somebody has an idea please?
The result of the first query is a count, not a count by host
eventtype="AppliService" Name="mfevtp"
| fields Name, host
| dedup host Name
| stats count
count
1000
If you want to use the host searching later you need to include it in the stats count
eventtype="AppliService" Name="mfevtp"
| fields Name, host
| dedup host Name
| stats count by host
Then you;ll be able to search the latter
The result of the first query is a count, not a count by host
eventtype="AppliService" Name="mfevtp"
| fields Name, host
| dedup host Name
| stats count
count
1000
If you want to use the host searching later you need to include it in the stats count
eventtype="AppliService" Name="mfevtp"
| fields Name, host
| dedup host Name
| stats count by host
Then you;ll be able to search the latter
thanks tiago
thanks a lot