Hi Team,
search sourcetype=my_logs source.item_id=34324234324| stats count by event_type
and
search sourcetype=my_logs source.folder_id=4324324324 | stats count by event_type
Can someone help me to merge the above two searches to a single one please
sourcetype=my_logs source.item_id=34324234324 AND source.folder_id=4324324324| stats count by event_type
you don't have to put a "search" at the front.
You mean like this?
sourcetype=my_logs source.item_id=34324234324 OR source.folder_id=4324324324 | stats count by event_type