I have lots of indexes All of the Organizations have there data in indexes with only two letters like index=os
I want to do a search like this [ *| stats distinct_count(host) by index ]
to find all the hosts for each org but I only want the indexes with two letters.
I tried this [ * | regex org="index=(?\w\w)\s" | stats distinct_count(host) by org ]
but it did not work
Can anyone help
Try using rex instead:
index=* |rex field=index "^(?P<org>\w\w)$" | stats distinct_count(host) by org
It should grab only indexes with 2 letter names, and create a field called org.
Try using rex instead:
index=* |rex field=index "^(?P<org>\w\w)$" | stats distinct_count(host) by org
It should grab only indexes with 2 letter names, and create a field called org.
Thanks this worked