I'm not able to rename file names to display in a pie chart...any help would be appreciated...
I tried both ways..
index=web_server sourcetype=web_access (file="pr.prod" OR file="cr.crt" OR file="src.jsp") SESSIONID!="-" | dedup SESSIONID | stats count by file | rename "pr.prod" AS "Products", "cr.crt" AS "Category", "src.jcp" AS "Search"
index=web_server sourcetype=web_access SESSIONID!="-" | dedup SESSIONID | stats count(eval( file="pr.prod")) AS Products, count(eval(file="cr.crt")) AS Category, count(eval(file="srchjsp")) AS search | stats count by file
The rename command changes the name of a field, not the values of a field. To change values, use the replace command.
index=web_server sourcetype=web_access (file="pr.prod" OR file="cr.crt" OR file="src.jsp") SESSIONID!="-" | dedup SESSIONID | stats count by file | replace "pr.prod" with "Products" in file | replace "cr.crt" with "Category" in file | replace "src.jcp" with "Search" in file
The second method looks to me like it should work.
The rename command changes the name of a field, not the values of a field. To change values, use the replace command.
index=web_server sourcetype=web_access (file="pr.prod" OR file="cr.crt" OR file="src.jsp") SESSIONID!="-" | dedup SESSIONID | stats count by file | replace "pr.prod" with "Products" in file | replace "cr.crt" with "Category" in file | replace "src.jcp" with "Search" in file
The second method looks to me like it should work.
Thankyou...It worked,I have also added count at the end of the search to display the count by file in pie chart...
.......... | replace "src.jcp" with "Search" in file| eval file_slice = count + "-" + file | fields file_slice, count