index=syslog | eval length=len(field1) | where length > 100 | table field1,field2
I want to create a search that, in addition to matching the length requirement of field1, also only displays results where a count of the occurrences of field2 is above 5.
@rotundwizard ,
Try
index=syslog | eval length=len(field1)|eventstats count as field2count by field2|where length > 100 AND field2count > 5
@rotundwizard ,
Try
index=syslog | eval length=len(field1)|eventstats count as field2count by field2|where length > 100 AND field2count > 5