Hi,
Currently I am showing 1 datapoint per column with below query:
application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" ) | timechart span=1d count | eval day=strftime(_time,"%d/%m") | fields day, count
but I want to show 3 data for each daily column, I am trying below
application="my-app" "*test-path*" | rename test-path as path | eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order ) | timechart span=1d count | eval day=strftime(_time,"%d/%m") | fields day, count
but not working
1) You are missing a close-quote on "Total order".
2) Your timechart
needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.
application="my-app" "*test-path*"
| rename test-path as path
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order")
| timechart span=1d count by result
| eval day=strftime(_time,"%d/%m")
| fields day, "Total count", "Total order"
1) You are missing a close-quote on "Total order".
2) Your timechart
needs a "by" field in order to separate the counts for the two different results.
3) The final record needs to have the two fields you wanted in it.
application="my-app" "*test-path*"
| rename test-path as path
| eval result=case((path == "/test-data/test/data"), "Total count" , (path == "/test/test2-mydata/order"), "Total order")
| timechart span=1d count by result
| eval day=strftime(_time,"%d/%m")
| fields day, "Total count", "Total order"
Thanks @DalJeanis