hi
I use the search below and I call it from a loadjob command
After the loadjob execution, I need to filter the data by host but it doesnt works
I had | table host after | stats dc(host) but nothing happends
what is the problem please??
`AppliService` Name="wuauserv"
| fields Name, host
| stats dc(host)
| loadjob savedsearch="admin:TEST_sh:FO_EventServiceLog_Serv_1"
| search host=$tok_filterhost$
Add AS host
to the first search, like this:
`AppliService` Name="wuauserv"
| stats dc(host) AS host
@jip31
Your first search is not returning host
field. So the filter might not work for you.
You can try this instead.
First search
`AppliService` Name="wuauserv"
| fields Name, host
Second Search
| loadjob savedsearch="admin:TEST_sh:FO_EventServiceLog_Serv_1"
| search host=$tok_filterhost$
| stats dc(host)
thanks to you, I test in a few days and keep you aware
@jip31
Did you get a chance to test this?