Hello,
I'm creating a visualization and attempting to show the total amount of events, and break them down by a specific field.
So my initial search would be something like the search below, where I just count all the events for a specific sourcetype.
index=foo sourcetype=bar | stats count as "Total Events for Security Control"
The other searches would filter these by evaluating a third field and counting the ones that are true for the condition and the ones that are not.
index=foo sourcetype=bar baz="Blocked" | stats count as "Total Blocked"
index=foo sourcetype=bar baz!="Blocked" | stats count as "Total Blocked"
The issue that I'm seeing is that for one of my sourcetype, the total number of events is not equal to the sum of the breakdown searches. Any idea as to why this might be happening?
... View more