For context, I'm creating a dashboard where a user can search activity of all hosts in an environment or one host in that same environment. Unfortunately, the naming convention used for hostnames makes searching all hosts in a specific environment a bit more complicated than using a single field/value pair with a wildcard. For example, searching all non-production hosts would require a search similar to the following in my case: index=servers host!="*prd*" AND (host="*30*" OR host="*40*") In the dashboard, I'd like the user to be able to select a single hostname from a dropdown, or an "All Servers" option from the dropdown. With that being said, is there a way I can map all the hostnames to a single "field value" such that something like... index=servers host=allhosts ...would accomplish the same thing as my initial search example? This would be helpful as it would allow me to use a token for the host field when a user selects an option from the hosts dropdown.
... View more