The objective of this search is to count the number of events in a search result. This is the current search logic that I am using (which uses the linecount command):
sourcetype="my_source" filter_result="hello_world" | stats sum(linecount) as Total
Is there an "eventcount" command that simply counts the number of events that I can use instead of "linecount"? The reason is that linecount sometimes over-counts some results (i.e. it will count 100 when there are actually only 75 events).
Thanks!
Hello
Linecount is the number of lines per event
I guess you are looking for something like:
sourcetype="my_source" filter_result="hello_world" | stats count as Total
Regards
Here is a way to count events per minute if you search in hours:
* | timechart count(_raw) span=1h
I finally found something that works, but it is a slow way of doing it.
index=* [|inputcsv allhosts.csv] | stats count by host | stats count AS totalReportingHosts| appendcols [| inputlookup allhosts.csv | stats count AS totalAssets]
Hello
Linecount is the number of lines per event
I guess you are looking for something like:
sourcetype="my_source" filter_result="hello_world" | stats count as Total
Regards
Yes, this is exactly what I was looking for. I just tested it and it works. Thank you!