We want all the hosts in index=aws that are NOT in index=windows.
Example :
| tstats count where index=aws by host | table host
| search NOT [| tstats count where index=windows by host | table host]
Hi, please try this:
| tstats
dc(index) AS index_count
WHERE index IN (aws,windows)
BY host
| where index_count=2
| table host
Ciao.
Giuseppe
Hi. Your search is so close to what I do.. change search -> where
| tstats count where index=aws by host | table host
| where NOT [| tstats count where index=windows by host | table host]