source=*.log host=myhostname "provider=microsoft" "status=SENT_TO_AGENT" | timechart dedup_splitvals=t limit=10 useother=t count AS "Count of Event Object" by provider format=$VAL$:::$AGG$ | fields + _time, "*"
This will display a count of entries in the logs that say "SENT_TO_AGENT"
I want to display an average line chart for previous 3 months, and the current month as an overlay over the previous months.
What does your timechart currently give you? Daily counts, hourly counts? What does "average" mean in this context? Does previous 3 months include the current month or only complete months prior to the current month?
Please provide some sample representative anonymised events and a representation of what your output results would be (as a table not a graph).