All,
LOVE the patterns tab. Is there a way for me to get that as an emailed scheduled search for my users?
Yes, you can. Just click a pattern, then click Create alert in the pattern information area on the right.
Yes, you can. Just click a pattern, then click Create alert in the pattern information area on the right.
Yup, and you can add | cluster t=0.3 labelonly=true labelfield=_patterns match=termset | findkeywords labelfield=_patterns dedup=true
to any base search to identify clusters of events if you want to build your own view.