I have a field which contents is a telephone number.
if I do:
host=ivr* | chart sparkline count by FIELDNAME
I get a graph for every FIELDNAME but what I want is a linegraph over time of top 20 FIELDNAME in one linegraph.
any ideas?
host=ivr* [search host=ivr* | top 20 FIELDNAME | fields FIELDNAME] | timechart count by FIELDNAME
host=ivr* [search host=ivr* | top 20 FIELDNAME | fields FIELDNAME] | timechart count by FIELDNAME
You can solve this using a subsearch for grabbing the top 20 FIELDNAME values, then use these results in the outer search, so it only looks for data with one of these FIELDNAME values.
host=ivr* [search host=ivr* | top 20 FIELDNAME | fields FIELDNAME] | chart sparkline count