I would like to get a ratio of errors by app_pool, and then compare it to 5, 10, 1hr ago?
tag=java | stats count as "Events" by app_pool | appendcols [search tag=java tag=problem | stats count as "Problems" by app_pool]
I am thinking a running summary index counting errors and counting events by app_pool, then a search which compares things after the fact? Is there a better way to do this?
tag=java earliest=@d | timechart span=1h count as Events count(eval(tag=problem)) as Problems | eval ratio=round(Problems/Events, 2)