Hello,
I hope someone could help me out figuring out this one out. The core of what I am trying to do is get a list of all event codes in an index and source sorted on source to understand what is sending information if I am missing anything.
index=acg_eis_auth EventCode=* | dedup EventCode | fields EventCode
| stats count by EventCode
Hi @Huss54,
Please try below;
index=acg_eis_auth EventCode=*
| stats count by EventCode source host
| sort - count
Remove the dedup command. Deduplicating a field before counting that field means every value will have a count of 1.
Hi @Huss54,
Please try below;
index=acg_eis_auth EventCode=*
| stats count by EventCode source host
| sort - count
Thank you so much that was exactly what i was looking 🙂