Hello, Thanks for your assistance. I will accept your solution. Can you also comment below? The *** groups of commands***, I meant ** group of searches*** , will use this term moving forward W...
See more...
Hello, Thanks for your assistance. I will accept your solution. Can you also comment below? The *** groups of commands***, I meant ** group of searches*** , will use this term moving forward When I checked "enable summary indexing" on a scheduled report, it automatically appended the following statement at the end of the searches | summaryindex spool=t uselb=t addtime=t index="summary" file="[filename].stash_new" name="test_ip" marker="hostname=\"https://test.com/\",report=\"test_ip\"" index=summary report=test_ip | dedup sourcetype sourcetype is stash, while the original sourcetype is syslog I read the link you sent, it states that if I change the sourcetype, it will incur license usage: sourcetypeSyntax: sourcetype=<string>Description: The name of the source type that you want to specify for the events. By specifying a sourcetype outside of stash, you will incur license usage.This option is not valid when output_format=hec.Default: stash The solution you suggested is: split the events so it won't have multivalues before the summary index.. Or can I split multivalues after summary index? Thanks