I'm trying to figure out how to query all of the events from an Apache log and produce a report with counts of the number events with request_time less than 3s, less than 2s and less than 1s.
Thanks for the side message.
cms.apache-access | eval request_time_num = tonumber(request_time)
| eval category = case(
request_time_num < 100000, "<1s",
request_time_num < 200000, "<2s",
request_time_num < 300000, "<3s"
)
| stats count by category