I have a query for Windows updates per host. But I NEED to put those on a map. Is it via ''geostats''????
index=* host=*
sourcetype="WinEventLog:System" eventtype=windows_system_update
| timechart sum(eval(eventtype="eventlog_Update_Successful")) as Installed sum(eval(eventtype="eventlog_Update_Failed")) as Failed
↧