Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how do I combine " |stats count by host " and "| stats distinct_count(host)" in one table?

$
0
0
I can search for events and run stats count by host. And I can run a search of distinct number of hosts. I want to combine both in one table. I want count of events by host and a count of hosts. I actually want to create an alert based on the number of hosts returned.

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>