I have several things that come in via different platforms : Android (watch, phone, tablet), iOS (Watch, Phone, Tablet), and Web . For counting purposes I just need to know the platform (for now). I was wondering if there was any way possible to group my counts by my replaces .
index =blah source=blah earliest=-16m@m latest=-1m@m
| stats count(eval(Status=0 OR Status=1)) as Now by Platform
| replace android* with Android, *Web* with Web, ip* with iOS
| table Platform, Now
As of now my results look like:
What I would like:
Thanks in advance for any help.
... View more