When i use below query i can see multiple servers in the index.
Index=abc sourcetype=vmstat (host=windows1* OR host=windows2* OR host=windows3*) | eval cpu_percent_util=(100-pctIdle) | timechart span=1m avg(cpu_percent_util) by host
i can see graph by windows1, windows2, windows 3 but i want to see the host names like Web1, Web2, Web 3
Please help me on this.
You need a way to map from one name to another - how do you know whether windows1 is Web1 or Web2? Is this mapping stored in a lookup somewhere, do you include it in a case statement in the search, can you get it through a join with another search?