I have a simple query that produces a stacked bar chart as follows:
| table time, info_owner_deptBusiness, avg_data_residualRisk_max
| chart count(avg_data_residualRisk_max) over time by info_owner_deptBusiness
I would like to group my events by "time" in buckets of 5 minute intervals. My time stamps look like this:
How can I accomplish this while preserving the stacked bar chart visualization?
| bin span=5m _time
| chart count(avg_data_residualRisk_max) over _time by info_owner_deptBusiness
View solution in original post
Perfect, thank you!