I have the code below and I need to get the statuses yesterday and today with respect to API value.
My current search is below.
index="l7" earliest=-1d@d latest=now
| eval status=case(response_status<400 AND severity="Audit", "Success_count", response_status>=400 and response_status<500, "Backend_4XX",response_status>=500, "Backend_5XX",response_status==0 AND severity="Exception", "L7_Error")
| eval Day=if(_time<relative_time(now(),"@d"),"Yesterday","Today")
I need my data to be grouped separately or side by side.
I need your help in achieving this.
You can't have two level headers, but you could try combining the values
index="l7" earliest=-1d@d latest=now
| eval Day=if(_time<relative_time(now(),"@d"),"Yesterday","Today")
| eval status=case(response_status<400 AND severity="Audit", Day."_Success_count", response_status>=400 and response_status<500, Day."_Backend_4XX",response_status>=500, Day."_Backend_5XX",response_status==0 AND severity="Exception", Day."_L7_Error")
| chart count by API status
Can you please help with time range for 15mins ago in comparison to 15m last week ago.
Try something like this
(earliest=-7d@m-15m latest=-7d@m) OR (earliest=-15m@m latest=@m)
This did the trick.
index="l7" earliest=-1d@d latest=now
| eval status=case(response_status<400 AND severity="Audit", "Success_count", response_status>=400 and response_status<500, "Backend_4XX",response_status>=500, "Backend_5XX",response_status==0 AND severity="Exception", "L7_Error")
| bin _time span=1d
| timechart count by status
| timewrap 1d
It summed up the counts, I want all the several count wrt the API names which are over 100.
something like the screenshot above
You can't have two level headers, but you could try combining the values
index="l7" earliest=-1d@d latest=now
| eval Day=if(_time<relative_time(now(),"@d"),"Yesterday","Today")
| eval status=case(response_status<400 AND severity="Audit", Day."_Success_count", response_status>=400 and response_status<500, Day."_Backend_4XX",response_status>=500, Day."_Backend_5XX",response_status==0 AND severity="Exception", Day."_L7_Error")
| chart count by API status
Thank you for the response. It's working now