Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

I would like to create a pie chart based on "keywords" found in a field.

$
0
0
index=timswindows sourcetype=ActiveDirectory [search index=timswindows sourcetype=WinEventLog EventCode=4624 Account_Name!="-" | dedup Account_Name | stats values(Account_Name) as sAMAccountName] | dedup distinguishedName |fields sAMAccountName, distinguishedName, host |chart count by distinguishedName The field in question is "distinguishedName". There about 4 possible keywords that could be in this field. How do I filter them out in the chart.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>