I searched the error events and use the "cluster" operator as below:
error | cluster | table cluster_count _raw
I got a list of clusters with the size of each cluster as below:
1 98 192.168.11.37 - - ..." 2899 4035
2 4 Apr 13 15:03:10 1.1.1.1 ... (2006-04-13 15:02:40)<000>
3 12 Jan 14 09:47:14 ...(2005-01-14 09:48:21)
...
Now I click the cluster size (98) to look for the 98 events in that cluster, however, there is only one event displayed. Is there anything I did wrong?
LL