I thought it would be easier, but now I need to ask you for help.
I need to make a simple tart chart with the percent of an IP Address and the percent of all other together as "Other".
How can I group all values in a single value "other" but leaving out just the value I want to analyze?
I am currently using this query but it seems a bit hard for the search head:
index=logs sourcetype=more_logs dest_ip=*
| eval address=IF(LIKE(dest_ip, "0.0.0.0"), "YES", "OTHER")
| stats count by address