Hi all,
I was wondering if there's a way to create a search that I can add to a dashboard that'll present the Peak day and what the volume is over a 30 day period?
Essentially when loading into the dashboard I was hoping it could save whatever day it occurred and not be replaced until a larger peak occurs. Assuming that's even possible.
Possibly worded this poorly so feel free to ask any questions about what I'm trying to achieve.
This is a little vague so I will make some assumptions.
Assuming you want a daily count of events, and just keep the highest one, you could do this
| bin _time span=1d
| stats count by _time
| eventstats max(count) as max
| where count==max
Yeah my sincerest apologies, can have difficulties at times with accurately describing what I'm looking for.
I'll definitely checkout the below query.
But essentially I'm just looking for a date value and request value to not change day to day unless the request value is higher on a different date value. Hopefully that's a more accurate description.