Hello
im running this query:
((index=ssys_internal_fdm OR index=other_fdm) AND sourcetype!=machine)
source=*
| stats values(*) as * earliest(_time) as first_time latest(_time) as last_time by SerialNumber
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(first_time) as first_time ctime(last_time) as last_time
| search SerialNumber=D00520
| table Region PrinterType SerialNumber first_time last_time
since this SerialNumber exists in two indexes im getting this result:
> Region PrinterType SerialNumber first_time last_time
INTERNAL Dorado_F370 D00520 2019-03-20 00:15:10 2019-06-17 19:52:05
OTHER Stratasys F370
this is a very good result for another report but i need it to be in separate rows
is it possible ?
thanks
Hi,
If you want result based on SerialNumber and Index then please try below query
((index=ssys_internal_fdm OR index=other_fdm) AND sourcetype!=machine)
source=*
| stats values(*) as * earliest(_time) as first_time latest(_time) as last_time by SerialNumber, index
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(first_time) as first_time ctime(last_time) as last_time
| search SerialNumber=D00520
| table Region PrinterType SerialNumber first_time last_time
Hi,
If you want result based on SerialNumber and Index then please try below query
((index=ssys_internal_fdm OR index=other_fdm) AND sourcetype!=machine)
source=*
| stats values(*) as * earliest(_time) as first_time latest(_time) as last_time by SerialNumber, index
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(first_time) as first_time ctime(last_time) as last_time
| search SerialNumber=D00520
| table Region PrinterType SerialNumber first_time last_time
perfect ! thanks