There are three different events. Each event has the same fields. The fields I am focusing are "NumberOfRecords" and "Message"
Event 1 - Message: "Promote" NumberOfRecords:*2
**Event 2* - Message: "Evaluate" NumberOfRecords:*3
**Event 3* - Message: "Retire" *NumberOfRecords:*1
I am in in need of an if statement (or any other method) that will combine these three events and returns all three counts with headings to designate which event it came from.
Example: if message = "Promote" then return 2 as the count for "Promote Count" and so on.
I am able to his is individual queries such as:
NameOfJob= GH0A | spath NumberOfRecords | search NumberOfRecords=*| spath message | search message="PROMOTE"
However, I would like to do all three in one search. Any help is appreciated. Thank you
what does this one gives you?
NameOfJob= GH0A | spath NumberOfRecords | search NumberOfRecords=*| spath message | stats sum(MunberOfRecords) by message
how about this one?
NameOfJob= GH0A | spath NumberOfRecords | search NumberOfRecords=*| spath message | stats values(MunberOfRecords) by message
what does this one gives you?
NameOfJob= GH0A | spath NumberOfRecords | search NumberOfRecords=*| spath message | stats sum(MunberOfRecords) by message
how about this one?
NameOfJob= GH0A | spath NumberOfRecords | search NumberOfRecords=*| spath message | stats values(MunberOfRecords) by message
Both queries provide exactly what I need. Thank you greatly for your help.