I'm trying to combine results of varying operating systems into one, for example:
Microsoft Windows Server 2008
Microsoft Windows Server 2008r2
Microsoft Windows Server 2012
All to be listed as
Does anyone know I may do this? I tried this but wouldn't work:
...chart count(signature) by operating-system | eval sort_field=case(operating-system=="Microsoft Windows*",Windows Server)
You can also use field aliases in this case, refer the below link for more info and let me know if it works for you.
Three problems with your
operating- use single quotes to enclose non-standard field names.
=="Microsoft Windows*looks for literal equality, use
match()to allow regex-based matches.
Windows Servershould throw syntax errors, enclose strings in double quotes.
Thanks for this.
Still struggling though, I have changed to the following:
...chart count(signature) by operating-system | eval sort_field=case('operating-system'=match('operating-system',"Microsoft*","Windows Server",0))
The arguments to the 'match' function are invalid.