I would like to have some chart ( bar etc.) and table of logs which contain two information titleID and userID.
I would like to have table and chart of each user and sum of each titleID for him.
I'm using this search, but I'm not sure about it:
... | top "data.titleID" by "data.userID" | table "data.userID" "data.titleID" count
hi did you already tried with
your_search | stats sum(titleID) AS titleID BY userID | sort -titleID
if in addition you like to have only the first 10 top values you can add tho the above search
| head 10
No it's not a number, sorry that I didn't specify it properly, "data.titleID" is some string and I would like to have stats of how many times each user has used each data.titleID
oh yes, because my log contains field data which contains titleID and orderID so to get them it's data.titleID and data.orderID
According to the comments, I think you want something like this
| stats count by data.userID data.titleID | sort- count
So this query will give you the stats of how many times each data.userID has used each data.titleID.
let me know if this helps!