Hi,
Output of the below query has been attached, I need only the total value to be displayed in the dashboard.
Here the total value is 578 only that should be displayed in the dashboard
index=abc sourcetype=xyz
| rex field=_raw "INFO\s+(?<action>\w+\s\:?\s?\w+\s?\w+\s?\w+\s?\w+\s?\w+)"
| search action="getActiveRecords response" OR action="SUCCESS : get active records"
| stats count by action
| addtotals count col=t row=t labelfield=action label=output
You should be able to add another two lines to filter out the other stuff:
| search action=output
| table Total
You should be able to add another two lines to filter out the other stuff:
| search action=output
| table Total