I use the code below for doing a pie chart
index=windows sourcetype="wineventlog:system" SourceName="Disk" EventCode=7 Type="Critique" | dedup _time | stats count by EventCode | eventstats sum(count) as Total | eval percent=round((count/Total)*100,1) | eval EventCode=EventCode."(count: ".count.", percent: ".percent.")"
I need to update automatically this pie chart from an input token which represents the hostname.
I have something like this, but it doesn't work.
| stats count by EventCode, host
have you an idea please???
if you just want to filter based on the host name from the token, then try adding this to your base search.
index=windows sourcetype="wineventlog:system" SourceName="Disk" EventCode=7 Type="Critique" host=$hostname$
pearhaps I have bad explained
my token works with * or with an exact host
but i would like to have no pie chart if a wrong host is entered in the token
even with a wrong host actually my pie chart is always displayed....