I have a simple query that produces a stacked bar chart as follows:
index=xxx | table time, info_owner_deptBusiness, avg_data_residualRisk_max | chart count(avg_data_residualRisk_max) over time by info_owner_deptBusiness
I would like to group my events by "time" in buckets of 5 minute intervals. My time stamps look like this:
How can I accomplish this while preserving the stacked bar chart visualization?