So i am trying to link this to a token from another panel but since "message_id" is a created field, it doesn't work. Is there anyway I can make this work?
<index> <host>
| eval message_id=AREA.SUBID
| stats count by USER, TEXT
| search message_id="$messid1$"
| sort - count
Hi @Goldenfit ,
after a stats command, you have only the fields in the stats command, in your case: count, USER and TEXT.
So you cannot have message_id for searching after the stats command.
You have to put the search command before the stats or add the message_id field to the stats.
Ciao.
Giuseppe
It's not that message_id is a "created field".
You may need to set a token to $results.message_id$ as part of the <done> element of your query, but you have a bigger problem: the message_id field doesn't exist.
The stats command transforms the results so the only fields passed to the rest of the query are 'count', 'USER', and 'TEXT'. There is no message_id field to search for or to use in another panel.
So basically i have another panel
my goal is that when I click on one of the message_id displayed in the chart above, my first query in the original post udates it to display TEXT and USER with this particular message_id