How is it not working? No results or wrong results?
index=sdsf | search eventtype="*service*" or eventtype="*window*" | stats count by eventtype
HI @chuck_life09,
try to put the search conditions as in the main search as possible:
index=sdsf (eventtype="*service*" OR eventtype="*window*")
| stats count by eventtype
How is it not working? No results or wrong results?
index=sdsf | search eventtype="*service*" or eventtype="*window*" | stats count by eventtype
Thank you this worked, it dint show me results that were pertaining to "service" or "window". now it is showing me the events which has either of those 2 words.