I am looking to create a report to show just a subset of my Universal forwarders. What I am looking for is an expansion on this that I just cannot seem to get working. Any assistance appreciated! | tstats values(sourcetype) AS Sourcetype dc(sourcetype) AS #sourcetypes WHERE index=* by host for just the following indexes: os, main, tomcat. A great help would be to sort by deployment App (NIX, Unix, Linux) if possible, but I am not seeing anything in the system that shows the source of the data (which App is deployed).
... View more