Hi all,
I have below query and the results like below table, is there a way that only search and display total count for the Users who have error(User1, User2, User3)?
index=aaa sourcetype=...
Hi
I have a basic question about the append limit which is 50000 events max
Does it means that only the 50000 first events sorted by timestamp are displayed (from newest to oldest)?
And in s...
...ourcetype=ironport mailto=%form_var%
which will result in a fields that I can use (icid) to then find the mailfrom field. So I am thinking about a subsearch like:
index=email sourcetype=i...
index="_internal" user!=admin | [search index="_internal" | stats count by user]
I am trying to run above query but it fails with an error that "Error in 'SearchParser': Subsearches are only v...
...o go about this?
I tried using Map and the following, but neither seemed to work.
index=voice [search index=voice "ani" "8005558508"
| rex field=_raw "{\"ani\",\"(?<ani>\d*)\"}"
| rex f...
Hello,
Help me please. I'd like to define multiple search or subsearch to merge all relevant information about alerts.
Interesting fields in search are the hosts - as managed_host field a...
Hello I want to ask a question aboutsubsearch. When submitting a fed command without using it, an error message occurs as follows.
Before setting federated search ] index=fw | join s...
Have a search that returns emails of interest (possibly malicious). Trying to add a subsearch that will return a count of how many times each sender address has been seen in the last 30 days (r...
...n the metadata results but I need to have them show in the final results.
I was thinking a subsearch would work but it fails to match up all the records. I only get about 20 matching records but it d...
..." only returns about 300 results, but the subsearch is searching across millions of users accounts. If I removed the sub search, the outer search only takes a few seconds to complete.
Does a...