Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

stats count by source type missing some sourcetypes otherwise present

$
0
0
index=app_xxxxxxxxx_products cluster_name=dxx-exx-awslab sourcetype=xxxxxxx:deployment-info | stats count by sourcetype returns count for the sourcetype but when ran as : index=app_xxxxxxxxx_products cluster_name=dxx-exx-awslab | stats count by sourcetype the results doesn't include the sourcetype mentioned in firsts query

Viewing all articles
Browse latest Browse all 47296

Trending Articles