|
I want to group the cluster value based on the similar punct. I have used the following query. tag="tagname" sourcetype="sourcetype" ERROR | cluster t=0.9 showcount=true field="punct"| sort - cluster_count | head 10|table punct cluster_count But it is not able to distinguish the different punct like below and gives the count as combination of the count of 1st and 2nd punct. --::,[/#-]:__:.:_://...:/?=&=&=----& --::,[/#-]:__:.:_://...:/?=.&=----&= tag="tagname" sourcetype="sourcetype" ERROR|stats count by punct|sort - count|head 100 All suggestions are welcome! |
|
I was able to resolve this issue using the delim inside the cluster query. tag="tagname" sourcetype="sourcetype" ERROR | cluster t=0.9 showcount=true field="punct" delims="&$%"| sort - cluster_count | head 10|table punct cluster_count You can add more symbols inside the delims to distinguish the punct uniquely delims="&$%" |