I'm trying to set up a pie chart displaying the average response time to a particular server. The pie chart should have 3 buckets of varying width, corresponding to the average response:
1st bucket: 0 <= Response Time < 6
2nd bucket: 6 <= Response Time < 24
3rd bucket: Response Time >= 24
I am not sure how to do this in Splunk; span seems to only take fixed values in determining bucket widths. I've currently just been using chart with span=6, but it would be a huge advantage to split up the data into the 3 buckets described above.