Hi - I have a query as below
index=xxx "Project Id"
| rex field=_raw "Project\s*Id\s*-\s*(?<ProjectID>\d+)"
| eval eventTime=strftime(_time, "%m/%d/%Y %H:%H:%S")
| table eventime ProjectId
It presents the table perfect - basically when a Project does anything on the system.
I would like a heatmap if possible - when I select the one built in - it just shows the highest project ID Number - I would like an heatmap of the time I guess so I know when the system is being used.
The other thing is when I do a visualization - lets say the Project ID is 2000 - it shows as 2,000 in the Bar chart or any other chart.