- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to make eventstats results persistent?
drosse
New Member
08-15-2018
07:03 AM
I am using event stats to get a unique count of the number of different values that are present in a given field. However the specific field that I am counting on changes based on the sourcetype. The eventstats commands I have look something like this (there are several hundred in total so it's not feasible to do manually)
sourcetype=123 | eventstats dc(file_path) as uniqueCount
sourcetype=456 | eventstats dc(hash_value) as uniqueCount
I need a way to be able to store the results of the eventstats command so that it is appended to the original event and I am able to retrieve it for use in dashboards. I tried using collect and sistats and neither one stores the "uniqueCount" value.
Thanks
