Hello
I have this command:
| metadata type=sourcetypes index=wineventlog
The problem is that there are returned multiple lines for "WinEventLog" sourcetype so I dont understand why that when the names are absolutely same.
I expect to get 1 line per sourcetype.
If I search with index=wineventlog and stats by sourcetype - there is no problem so it is something with metadata command
Same issue for "wineventlog" sourcetype
Can you share sourcetypes returned from the search?
It could be because you have multiple sources. Check with:
| metadata type=sources index=wineventlog
It will likely show WinEventLog:Security, WinEventLog:System, etc.