Query:
index=new "application status" AND Condition=Begin OR Condition=Done |rex field = _raw "DIDS \s+\[?<data>[^\]]+)" |dedup data |timechart span=1d count by application
Result:
_time | application1 | application2 |
2022-01-06 | 10 | 20 |
2022-01-07 | 12 | 14 |
2022-01-08 | 18 | 30 |
I want to include Condition field as well in the table, how can i do it???
You can generally do this by concatenating the two data items into a single field for the split by clause of the timechart, i.e.
...
| eval split=application.":".Condition
| timechart span=1d count by split
Thank you @bowesmana it worked
@vishwa can you mark it as a solution so others can see it as a valid solution