I have a search as follows in which I am trying to display 2 fields
(My Search) | timechart span=1h count by field_username
which displays the result as follows
time usera userb userc user_d ----------------------------------
I don't want like this. All I am looking is as follows
time userslistofthatparticullarhour countofthat_hour
Thank you. Now is there any way I can display the result like listing out all the users for each hour and for each user displaying the list of fields for classname?..
Sorry If its confusing. I'm trying to display the list of users for each hour and besides that what each user is trying to do for example what he is trying to do information is available in a field called classname?
this should get you the count and distinct list of users by hour
base search | bin span=1h _time | stats count values(user) as users by _time
to solve your need you have to create a search like this
your_search | bin span=1h _time | stats count values(user) AS users by _time
Instead if you want to have only one column, for example to use in an Histogram you could merge two fields in one and do you timechart by that new field, something like this:
your_search | bin span=1h _time | eval Column=user+" - "+strftime(_time,"%Y-%m-%d-%H") | sort Column | stats count by Column
The choice to put before user or _time depends by what you want to emphasize.