case:
Logged events with differentiating fuellevel and the corresponding serial
Desired outcome:
So a graph with multiple lines, a line is based on a serialnumbers from the events, with vertically the value of a field within that same event.
Please help!
That's just a basic timechart.
your search that gets the events with _time serial and fuellevel
| timechart max(fuellevel) as fuellevel by serial
You can also try max(), min(), avg() first() last(), or any other aggregate command that seems relevant.
Thanks! That indeed gives me the max fuellevel per day! What is the option if I want to see it per event? Because some serials will have like 10 events per day and others will just have a few or even none on a day.
please send a sample of your data for better answer, however, I believe you are looking something similar to below:
index=x sourcetype=y | eval number = fuellevel - correspondingserial | timechart values(number) values(serial1) values(serial2)