Want to count all events from specific indexes say abc, pqr and xyz only for span of 1h using tstats
and present it in timechart.
Tried this but now working
| tstats count WHERE earliest=-1d@-3h latest=now index=ABC,PQR,XYZ by index, _time span=1h | timechart sum(count) as count by index.
| tstats count where index IN (windows,nix) by _time, span=1h , index
| chart values(count) as count over _time by index
Hi
You can try this:
| tstats count WHERE earliest=-1d@-3h latest=now index IN (ABC,PQR,XYZ) by index _time span=1h prestats=t
| timechart span=1h count as count by index.
You must use count on both and also span must be the same.
r. Ismo
NO, Getting graph only for first index.
Sorry, I just copied that from your example. It must be index IN (ABC, PQR,XYZ) or in the old way index = ABC OR index = PQR OR index = XYZ. Fixed into my previous reply.
| tstats count where index IN (windows,nix) by _time, span=1h , index
| chart values(count) as count over _time by index
Thanks, Working.