Hi,
I have this query
earliest=-4d index=wls OR index=main "ServletRequestImpl.java:2768" OR "rest path:/rest spec-version:2.5]] Servlet failed with Exception"|stats count avg(count) by host
And the results look like this
The count shows but no average count.... what am I missing?
Give this a try.
earliest=-4d index=wls OR index=main "ServletRequestImpl.java:2768" OR "rest path:/rest spec-version:2.5]] Servlet failed with Exception"| bucket span=1d _time |stats count by _time host | stats sum(count) as count avg(count) as avg by host
Replace avg with trend line for other requirement.
Give this a try.
earliest=-4d index=wls OR index=main "ServletRequestImpl.java:2768" OR "rest path:/rest spec-version:2.5]] Servlet failed with Exception"| bucket span=1d _time |stats count by _time host | stats sum(count) as count avg(count) as avg by host
Replace avg with trend line for other requirement.
Thanks somesoni2!!! Worked great!!!
You can't use avg(count) as the field count is not available before stats. What you want to show in avg count?
the average by day for each host
I'm guessing the same applies for Trendline?
earliest=-45d index=wls OR index=main "ServletRequestImpl.java:2768" OR "rest path:/rest spec-version:2.5]] Servlet failed with Exception"|timechart span=1d count by host| trendline sma2(count) as Trend
On this query I get the same count by host but no trendline