For each subject in the search sentence, the count number is displayed.
In addition to the information currently being displayed, I want to display the attached file name for each subject.
The search sentence you are using is below.
※ Partially omitted
index=xxxxx
| lookup ~ommitted~
| stats count ~ommitted~ by subject
Can I display the attached file name by adding it to the search sentence that is counting?
-image-
Subject | Number | attached file name | Number of Mail with Attachment
AAAA | 100 | aaaa | 10
BBBB | 50 | none | 0
CCCC | 200 | cccc | 200
In the current search searches, only the subject line and number of items are displayed.
*I want to display none if there is no attached file.
try...
| eval filename=coalesce(filename, "none")
| stats count values(filename) as filename by subject
try...
| eval filename=coalesce(filename, "none")
| stats count values(filename) as filename by subject
Thanks to your answer, I was able to solve the problem.