I'd like to run an efficient search over an index to find all of the types of 'vendor_action' field present in the data. However, this is a very large dataset so is there a low resource search to do this?
Hi @splunkymcsnypr,
You can use stats;
| stats count by vendor_action