For the query :
host=aeperf01api02 Level="INFO" | stats count by AppDomain
I have following output
I have 6 host like above, how to sort them in one query where I can present these output in rows and hosts in the column so that I can check what is the number of services hit by the particular host.
I want an image of the output.
For example, is this something like that?
host IN(aeperf01api02,AAA,BBB,CCC,DDD,EEE) Level="INFO"
| stats count by host,AppDomain
@JyotiP, instead of stats try the following chart command. The over host argument will put the host names in column and count by AppDomain.
<YourBaseSearchWithIndexAndSourceType> host=aeperf* Level="INFO"
| chart count over host by AppDomain
PS: As best practice make sure you include index and sourcetype in your Base search which is missing in your Splunk Search example.
View solution in original post