hi, i'm trying to get a simple pie chart of all my eventtypes for my dash board; the problem is that we currently have all log entries come in with the eventtype 'unix-all-logs'; which means not only am i double counting, but also has a rather large (50%) slice for the unix-add-logs.
is there a way i can remove just that entry from the output? or do i have to persuade who ever to not apply that eventtype to everything?
sourcetype=cisco_syslog | top limit=0 eventtype
Just remove the eventtype 'unix-all-logs' from your base search.
sourcetype=cisco_syslog AND NOT eventtype="unix-all-logs" | top limit=0 eventtype
He indicated that every log entry comes in with that eventtype, so won't this exclude all entries?