I am looking to chart a field that contains a request path but want to display and get a total count of all events that contain the root request path(a) and events that contain the root + <some guid>/contents.(b) The path is a field I manually extracted called "request_path_in_request" Example of the path I want to combine in the cart: (a)path=/v4/layers/asPlanted
(b)path=/v4/layers/asPlanted<some guid>/contents
Here is my Splunk query so far: source="partners-api-ol" request_path_in_request="/v*" | timechart count by request_path_in_request useother=f limit=10
And here is how that field is getting charted:
Is there a way to show only category of "/v4/layers/asPlanted" , but have the count be the total of all the events with that root path?
... View more