Hi,
We have a query that brings up the sourcetypes in correlated search using "tstats" Example: tsats datamodel xyz values(sourcetype) as sourcetype by host
result
sourcetype host
sourcetype 1 ABCDtest
sourcetype 2
.
.
.
.
sourcetype 1 ABCDtest
task here is i need tehe events where sourcetypes listed are more than one for a host and show up only those
Requirement
sourcetype host
sourcetype 1 ABCDtest
sourcetype 2
it should be something like addtotals or sum of sourcetype and like where sourcetype>1
Thanks in advance.
Add dc(sourcetype) as dc
to your tstats
, and add | where dc > 1
to your search pipeline.
Add dc(sourcetype) as dc
to your tstats
, and add | where dc > 1
to your search pipeline.
Thanks that works 🙂