 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		This is a little vague.  Are you using this in a dashboard?  Or just in the search bar or what?  Traditionally you would use the stats command to get a count of events.  
sourcetype=databaseError "object is null"  | stats count
But, if you're building a dashboard then you may want the events and the count both on the dashboard.  One as a single value field (using | stats count) and one as a table of events.
Perhaps you could clarify your use for this in order to help folks come up with the best answer?
Hello! Here is what you can do: sourcetype=databaseError|eval object_string=case(searchmatch("object is null"),"object is null")|stats count by object_string
You can take this as an example, with the _internal index:
index=_internal|eval error_tag=case(searchmatch("error"),"error")|stats count by object_tag
Are you looking for something more detailed than the obvious 'stats count'?
sourcetype=databaseError "object is null" | stats count
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		This is a little vague.  Are you using this in a dashboard?  Or just in the search bar or what?  Traditionally you would use the stats command to get a count of events.  
sourcetype=databaseError "object is null"  | stats count
But, if you're building a dashboard then you may want the events and the count both on the dashboard.  One as a single value field (using | stats count) and one as a table of events.
Perhaps you could clarify your use for this in order to help folks come up with the best answer?
