hello
I use a scheduled search where I stats events like this :
| stats last(LastReboot) as "Last reboot date" by host CATEGORY DEPARTMENT
For the moment, in DEPARTMENT field I have a lot of empty fields
In the dashboard, I call my scheduled search and I use token filters
| loadjob savedsearch="admin:SA_XXX_sh:LogLogon"
| search CATEGORY=$tok_filtercategory|s$
| search DEPARTMENT=$tok_filterdepartment$
What I dont understand is why the events are not displayed if DEPARTMENT fiel is empty?
Thanks
Hi @jip31,
stats command cannot group empty fields, you can try below;
| fillnull value="empty" DEPARTMENT
| stats last(LastReboot) as "Last reboot date" by host CATEGORY DEPARTMENT
Hi @jip31,
stats command cannot group empty fields, you can try below;
| fillnull value="empty" DEPARTMENT
| stats last(LastReboot) as "Last reboot date" by host CATEGORY DEPARTMENT