Dear All,
There are 3 source types and we are pushing data into same index we need to give the count based on each source type. I replied
Index= earliest ="-1y" latest ="now" | stats count by sourcetype.
is there any faster way to provide counts apart from this way?
Regards,
Santosh
↧