If you use the transaction function, the duration field exists.
So you have to redefine ranges with a new field like "durationrange" (see eval functions or rangemap)
Finally use "| sort -durationrange" at the end of the search.
As Yann was mentioning, once you have the
duration value from
transaction you can use
rangemap to do something like this:
... | rangemap field=duration 0-10=0-10 11-100=11-100 100-500=100-500 default=500+ | stats count by range
Thanks! I get some overlapping ranges and it gets displayed as
2-3 3-4 78
4-5 3-4 98
Is there any way to get the overlapped duration value assigned to a unique range.
for eg , duration of 2 should show up in 2-3 range and not in 1-2.