Dear All,
There are 3 source types and we are pushing data into same index we need to give the count based on each source type.
I replied:
Index= earliest ="-1y" latest ="now" | stats count by sourcetype.
Is there any faster way to provide counts apart from this way?
Regards,
Santosh
↧