Hi all, I'm trying to create category based on host category: Lab,Personal,Staff and get workstations to be counted for each category. I tried using below and it gives desired results however it doesn't work when I applied boolean expression (OR) on more details in certain category. <base search>| eval category = case(match(host,"ABC-*"),"Staff",match(host,"DESKTOP*" OR host,"PC-*"),"Lab",true(),"Personal")|stats count by category,host|sort -count|stats sum(count) as Total list(host) as Workstation_Name list(count) as count by category|where Total>1|sort Total Expected Result: category | Total | Workstation_Name | count Staff 5 ABC123 2 ABC345 3 Lab 2 DESKTOP123 1 PC123 1 Personal 1 Etc... 1 Any help would be much appreciated!
... View more