Hi ,
i have more that 22 SH and 18 indexers
i want to know the how may request are coming to each search head and indexer
Can someone help me with basic query for this
Surely you are joking about your numbers. In any case, try this:
index=_* sourcetype=audittrail action=search
| stats count BY user host
| sort 0 - count
| stats list(*) AS * BY user