I have an input of value is like an odometer so it's cumulative. I collect a sample every 15 minutes. If I want to create a timechart that shows the total value of 15 min duration. how would I do that? See example below.
1/17/2023 0:01:00 value 6
1/17/2023 0:02:00 value 6
1/17/2023 0:03:00 value 6
1/17/2023 0:09:00 value 7
1/17/2023 0:10:00 value 6
1/17/2023 0:11:00 value 7
1/17/2023 0:12:00 value 8
1/17/2023 0:15:00 value 8
from 1 minute to 15 minute total value is 54
1/17/2023 0:16:00 value 5
1/17/2023 0:17:00 value 8
1/17/2023 0:18:00 value 5
1/17/2023 0:29:00 value 7
1/17/2023 0:30:00 value 5
from 16 minute to 30 minute total value is 30
Try something like this
| timechart span=15m sum(value)
@ITWhisperer this is not working
Why/how?
What does it give you?
You need to use only one timechart command
| timechart span=15m sum(active_state) as active_state sum(idle_state) as idle_state
Looks like your extract is not working. Can you share some raw events in a code block?