Hi
Can anyone help me with below query
I have created a pie chart based on the error message, however i am not sure how to add country along
index=test
| iplocation Properties.ip
| dedup Properties.ip
| stats count by event.Properties.errMessage
You will either have to show the pie chart as a trellis chart so it shows one chart for each country or create a composite field containing both country and error message, as the pie chart can only show one dimension, i.e.
index=test
| iplocation Properties.ip
| dedup Properties.ip
| eval composite=country.":".'event.Properties.errMessage'
| stats count by composite
Then the composite will be Australia:OK and so on.
Create a composite field with the two labels concatenated and count by that
Create a composite field with the two labels concatenated and count by that
I am not sure how to create composite filed, could you please advice on this please