There are two types of messages I'd like to correlate in my logs:
I need a scatter chart showing the server load on one axis, and operation time in seconds on the other, with the points in the chart showing the load vs execution time of the operations.
The problem I'm having is, the field that announces the server load is not included in the same messages that announce the elapsed time for that particular operation. So when I'm searching for operations, I need a way to assign the last server load value that was logged before each operation message, to each individual operation message.
Let me know if this doesn't make sense :). I've been having a rough time working it out.
the time is probably your best join.
example :
source=logA format :
source=logB format :
a basic search may be like :
source=logA OR source=logB load OR duration | timechart span=5min max(load) AS load avg(duration) AS duration | table load duration
the time is probably your best join.
example :
source=logA format :
source=logB format :
a basic search may be like :
source=logA OR source=logB load OR duration | timechart span=5min max(load) AS load avg(duration) AS duration | table load duration
Novel solution, thanks!