I am trying to get where I have if the _time and host are the same I exclude those results. I was thinking an eval or where statement might do it, but I can't figure out the syntax for either one.
I tried stats to count(_time) and where count is >=2 to show the results to test but it gives me no results.
Any thoughts would help.
if you are trying to delete duplicates
eg:
2018-12-27 13:14:08 host
2018-12-27 13:14:08 host
you can use - | dedup _time host (you will have just 1 event left)
if you are trying to completely exclude the events, try using
| stats dc(host) as count by _time | where count =1