How is it not working? No results or wrong results?
index=sdsf | search eventtype="*service*" or eventtype="*window*" | stats count by eventtype
HI @chuck_life09,
try to put the search conditions as in the main search as possible:
index=sdsf (eventtype="*service*" OR eventtype="*window*")
| stats count by eventtype
Ciao.
Giuseppe
How is it not working? No results or wrong results?
index=sdsf | search eventtype="*service*" or eventtype="*window*" | stats count by eventtype
Hi,
Thank you this worked, it dint show me results that were pertaining to "service" or "window". now it is showing me the events which has either of those 2 words.