I'm doing this REST call to query the system for modular inputs:
| rest /services/data/modular-inputs | table title description
Before running this through the table command, the output was extremely wide because of the way this particular data has fields broken out. My ideal end goal is something like "make me a table of arbitrary REST command output but only include fields which are in every event". I started thinking how to do this with the metadata command when I realized that there is no index metadata to query as this data isn't indexed. Now, I'm out of ideas. TIA
One more workaround
| rest /services/data/modular-inputs | table [| rest /services/data/modular-inputs | fieldsummary maxvals=1| eventstats max(count) as max | where count=max | table field | eval field=field."," | mvcombine field | nomv field | rename field as search]
One more workaround
| rest /services/data/modular-inputs | table [| rest /services/data/modular-inputs | fieldsummary maxvals=1| eventstats max(count) as max | where count=max | table field | eval field=field."," | mvcombine field | nomv field | rename field as search]
I like this version. It comes out close to 50% faster in my slightly-scientific tests. Thanks!
Mildly hacky, but it works:
| rest /services/data/modular-inputs | fillnull value="§%&$&ZH$%%" | untable id field value | eventstats count(eval(isnull(value) OR trim(value)="" OR value="§%&$&ZH$%%")) as nulls by field | where nulls=0 | xyseries id field value
Nice one!!
Not sure which to pick! 🙂
The one that doesn't need to cheat with a subsearch of course 😛
I gave ya points. 🙂