I am trying to create a report that pulls a version, but only shows one instance and then list all the hosts within that version
Assuming you already have the fields extracted:
<your index search>
| stats count by Name Version host
| eventstats count by Name Version
| eventstats max(count) as top
| where count=top
I am searching for "Unified Payment Platform Version=" which contains the specific version of firmware from about 2000+ hosts.
The line I am searching may populate multiple times depending on if the device was rebooted.
The search I need:
- list all the versions, but only one count from each host
- if possible, the list the hosts on the version
Please share some anonymised representative events in raw format in a code block </>
[2024-04-17 10:23:37] [Lane 0] Application ID: Name=Unified Payment Platform Version=06.80.06-0032
Assuming you already have the fields extracted:
<your index search>
| stats count by Name Version host
| eventstats count by Name Version
| eventstats max(count) as top
| where count=top
You could try something like this
<your index search>
| eventstats count by Version
| eventstats max(count) as top
| where count=top