Hello,
I am facing an issue while I try reading from Rest API Splunk Aggregated info.
A query that uses the calculation below is able to provide 4 columns via UI but not via ADF Rest API where I get only the Total result. Seems to me like the issue is with the grouped data which can not be read for some reason. Any suggestion please?
| eval Days=(relative_time(now(), "@month+28d")-patchLevelDate)/86400 | where time>relative_time(now(), "-30d") | eval system="2. VDI Persistent" | eval compliant=if(Days<70, "Yes", "No")]
| chart count(host) by system compliant | addtotals