I want a report when total events less than 9500000 in a day from sourcetype.
Also I tried below query, but its giving me count as 0.
| tstats count where index="cb_protect" sourcetype = "carbonblack:protect" subtype=* | search count<9500000
Need a help in this scenario
If subtype is not an indexed field then tstats won't find it. Try the same search without subtype or use a non-tstats search.