I have a file call /net/dell569srv/dell569srv2/apps/qa10157_TPK0002437_24367887/TestRunner/logs/20170321-184649.17336.50.cmd.51.archive-and-report.sh.log
In this there are many events in this file, however i want to display all of them in a cell, is it possible to merge them?
I want all _raw events in one cell and to dedup the source.
Like this:
index=mlc_live host=TimeSeries sourcetye="TestRunner_logs" | stats list(_raw) BY source
Be aware that the stats
commands (e.g. list
) are limited to 1000 values inside a multi-value field so if you have more than 1000 events, you will only see the latest 1000 of them.
Like this:
index=mlc_live host=TimeSeries sourcetye="TestRunner_logs" | stats list(_raw) BY source
Be aware that the stats
commands (e.g. list
) are limited to 1000 values inside a multi-value field so if you have more than 1000 events, you will only see the latest 1000 of them.
This worked cheers.
Try like this
index=mlc_live host=TimeSeries sourcetye="TestRunner_logs" | stats list(_raw) as RawData by source
Thanks for this...