Hey guys. So I need to display a dashboard panel with a single line, the total count of all hits from the Palo Altos that are either High or Critical. First, I pull out the criteria.
sourcetype="pan_threat" (severity="high" OR "critical")
Now, when I timechart that (timechart count by dst_ip), it throws a few lines at me. So far so good. However, when I do the following:
sourcetype="pan_threat" (severity="high" OR "critical") | timechart sum(count) by dst_ip
It throws me back 0 results. Using eval fails in an even more spectacular way.
sourcetype="pan_threat" (severity="high" OR "critical") | eval total=sum(count) | timechart total by dst_ip
Error in 'eval' command: The 'sum' function is unsupported or undefined.
I'll fully admit I'm confused. Logically, all I want it to do is add count per hour, and plot that number on the graph, moving onto the next one. If I can type it in one sentence here, it shouldn't be that hard to do. What am I missing?