I need help to fine tune this query;
| eval pingsuccess=case(match(ping_status, "succeeded"), Number)
Basically, I want to create a new field for ping success that will show the event count as values.
let me understand: what are the values of ping_status?
if they are only "succeded" and "failed", you don't need anything:
index=network sourcetype=ping | stats count BY ping_status
if you have more values for ping_status that you want to aggregate you could use if or case functions:
index=network sourcetype=ping | eval pingsuccess=if(ping_status="succeeded"), "succeeded","failed") | stats count BY pingsuccess