case:
Logged events with differentiating fuellevel and the corresponding serial
Desired outcome:
So a graph with multiple lines, a line is based on a serialnumbers from the events, with vertically the value of a field within that same event.
Please help!
That's just a basic timechart
.
your search that gets the events with _time serial and fuellevel
| timechart max(fuellevel) as fuellevel by serial
You can also try max()
, min()
, avg()
first()
last()
, or any other aggregate command that seems relevant.
Thanks! That indeed gives me the max fuellevel per day! What is the option if I want to see it per event? Because some serials will have like 10 events per day and others will just have a few or even none on a day.
please send a sample of your data for better answer, however, I believe you are looking something similar to below:
index=x sourcetype=y | eval number = fuellevel - correspondingserial | timechart values(number) values(serial1) values(serial2)