Hi all, I would like extract from intranet weblog (IIS log) top pages grouped by departments to see which pages are most viewed by each department. I can use the cs_username field to identify the department and with the following query I can count the total activity by depertment: sourcetype="iis" index=intranet | fields cs_username |
rex field=cs_username "(?i)mydomain\\\(?<username>[^\s]*)" |
stats count as events by username |
table username events |
lookup address.csv Email as username | fillnull value=- |
stats sum(events) as total_events by department Now I would like to extract the most viewed pages (cs_uri_stem) grouped by department. How can I do that? Thank you in advance!
... View more