For some reason I'm hitting a wall on the logic of this search. I'm working with Palo Alto logs and the fields i'm interested in are the bytes and category fields.
Essentially I would need to sum the total bytes for all categories over a 30 minute period and then sum bytes for the streaming category for the same period, then display a line chart showing the comparison for the bandwidth used for the streaming category to the bandwidth used by all categories combined by minute.
Try the following: create a timechart, then addtotals, then remove all the unwanted category columns:
...your base search...
| timechart sum(bytes) by category
| addtotals
| fields _time,streaming,Total
Hi @digital_alchemy,
Try this,
your search |eventstats sum(bytes) as total|search category="streaming category"|timechart sum(bytes) as streaming_bytes,first(total) as total
He mentions he is looking for a linechart over time. So your eventstats should be by _time. Also: your last stats command will drop the totals.
thanks @FrankVI, forgot to add the total to the result