I am running the following query to get events from windows event logs for the past month. I want to restrict the search to extract only first 3 events for each event code. Any pointers please?
index=xxxx sourcetype=yyyy host=zzzz | table _time,host,EventCode,EventCodeDescription,_raw
Required output:
EventCode1
EventCode1
EventCode1
EventCode2
EventCode2
EventCode2
EventCode3
EventCode3
EventCode3
.
.
.
↧