I have events with an array field named "tags". The tags array has 2 fields for each array object named "name" and "type". I reference this array as tags{}.name. The values being returned for one event are: name, type Dept_Finance, Custom Asset_Workstation, Custom My goal is to count the events by tags starting with "Dept_". (index="index_name") | dedup id | stats count by tags{}.name This returns the correct count of tags for "Dept_" but it's also including all other tags that do not begin with "Dept_". The Asset_Workstation tag is attached to this event however I don't want it to output in the query. How can I pull records with multiple tags but exclude all tags not beginning with "Dept_" from the output? I know this is an easy thing to do but I'm still learning SPL. Thanks for your help.
... View more