I've this simple search that uses BY but it's not returning any results. Without the BY clause, it's returning the correct results.
source="C:\tmp\log4j2.log" bam error errorId BY errorId
any help is appreciated, thx. I already checked the sql ref
You will need to use the BY operator with a stats, chart or timechart commmand.
Example only :
source="C:\tmp\log4j2.log" error bam | stats count BY errorId
View solution in original post
| stats count(errorId) BY errorId