Hi,
i have events in one sourcetype with over 90 similar fields like field1, field2 ... field90.
I can write a query like: search index=a sourcetype=2 field1=* field2=* ..field90=* | stats min(field1), max(field1, min(field2), max(field2)
is there a way reduce the long query to something like: index=a sourcetype=2 field*=* | stats min(field*) max(field*) ?
THX
If _raw has a field
index=a sourcetype=2 "field*=*"|stats min(field*) as min_field* max(field*) as max_field*
※You can use wild cards for stats.
If _raw has a field
index=a sourcetype=2 "field*=*"|stats min(field*) as min_field* max(field*) as max_field*
※You can use wild cards for stats.
index=a sourcetype=2 |stats min(field*) as min_field* max(field*) as max_field*
Works fine, Thank you 🙂
Be sure to click Accept
to close the question.