Hi Binh, Thanks for reply,
But, I want to search php, css ,js and jpg count from example1.com then I think, I need to query like below: 1) "vhost:example1.com AND *.php" for php count. 2) "vhost:example1.com AND *.css" for css count. 3) "vhost:example1.com AND *.js" for js count. I think it looks bit odd. is their any other way around? On Wednesday, 12 February 2014 21:59:34 UTC+5:30, Binh Ly wrote: > > Pankaj: > > You should be able to pin a query on each dasboard to filter down to only > the log events that you're interested in. So for example in your first > case, you can pin a filter (query) like: > > vhost.raw:example1.com > > And everything in your current dashboard will narrow down to example1.comdata. > -- You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/53d3af4d-a2ed-4781-9c5b-fe6630f9a123%40googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out.