I am trying to perform a search that groups all hosts by sourcetype and groups those sourcetypes by index. So far I have this:
| tstats values(host) AS Host, values(sourcetype) AS Sourcetype WHERE index=* by index
But this search does map each host to the sourcetype. Instead it shows all the hosts that have at least one of the resulting sourcetypes as a sourcetype.
Does this help you?
How about this?
| tstats count where index=* by index sourcetype host | stats list(host) as Hosts by index sourcetype