Currently I am running the below query to generate a report based on appname,spacename,orgnameand foundation which takes longer to run(for the past 24 hours search). How do I create a summary index to efficiently use this query for faster results?
sourcetype="pcf:log"
| eval report_create_time=strftime(now(), "%Y-%m-%d %H:%M:%S,%3N")
| eval spanID_ = coalesce(span_id, SPAN_ID, x_b3_spanid, spanId)
|stats count(spanID_) AS spanCount by report_create_time cf_app_name, cf_space_name, cf_org_name, foundation
... View more