Does anyone have a good way (or am I missing the something obvious?) of calculating for a defined time range the average frequency of the events logged?
Such as eventtype A appeared every X minutes.
I would use eval in combination with stats. For example:
sourcetype=apache_error earliest=-60m | stats count as total | eval errors_per_min=(total/60) | fields error_per_min
This would take the total # of events over the past 60 minutes, then divide by 60 to get you a count per minute. Or from the advanced charting view:
sourcetype=apache_error earliest=-60m | timechart span=1m count as error_per_min
View solution in original post
I knew I missing something obvious 🙂