Hi, so currently I have the following panel and code:
index=origin sourcetype=access_combined (AccountID!="test" AND AccountID!="server") $AccountIDtoken$ | eval AccountID=if(isnum(AccountID), tag, AccountID) | chart count by AccountID, status_description
But what I WANT is for it to look kinda like this...
...With FOUR overlay lines (one for each response code total count). One axis would be account IDs (probably stacked), the other axis would be time slots. I have pickers for Timeframe (token=field1) and AccountID (token=AccountIDtoken) and timespan (token=span) in place.
That way I could see variation in response codes over time, per account. Any thoughts?
index=origin sourcetype=access_combined (AccountID!="test" AND AccountID!="server") $AccountIDtoken$ | eval AccountID=if(isnum(AccountID), tag, AccountID) | chart count by AccountID, status_description | addtotals | fields status_description, Totals
Now , go to the chart format and select all status_description as overlay
I'm afraid that search comes up as blank, even when running it in a search bar with the token removed. If I run it with just the "addtotals," it looks identical to before. The last pipe is stripping all the data for some reason.
have you explored streamstats ???