I'm doing an outputlookup at the end of the query, but I want to do it with a condition.
The condition is that Build=1511.
Do i have to use a where command or there is another solution please??
| dedup host
| stats count by host
[ search index="ai-wkst-windows-fr" sourcetype=WinRegistry key_path="\\registry\\machine\\xx"
| eval OS=if(key_path=="\\registry\\machine\\software\\xx),
| stats latest(OS) as OS latest(Build) as Build by host ]
| stats values(OS) as OS values(Build) as Build by host
| stats count as Total by OS Build host | fields - host | outputlookup build.csv