The splunk query below is only showing just one line of Metric_ID which starts at 1. I need help with the splunk query that we show all the 68 lines of Metric_ID starting from 1.
index=security sourcetype="Computers" "Computer Status"=Enabled| bin _time span=1day| dedup _time sAMAccountName| timechart span=1day count |search count > 0| stats avg(count) AS avg stdev(count) AS stdev min(count) AS min max(count) AS max latest(count) AS latest_count| eval min_thres=5000, max_thres=7500| eval alert=if((latest_count<min_thres OR latest_count>max_thres), 1, 0)| eval Metric_ID="1"| lookup free_metrics.csv Metric_ID output Data_Item_volatility, Metric_ID, Metric_Name
| eval Metric_ID="1"
>The splunk query below is only showing just one line of Metric_ID which starts at 1.
of course.>all the 68 linesI don't have any information here.