Hi all.
I have a search like this:
index=log sourcetype=data TYPE="PLATFORM" | timechart span=1d count by AREA limit=100 | addtotals
Now, I must replicate with a search like this:
index=log sourcetype=data TYPE="PLATFORM" | eventstats sum(QP) AS QTOTAL by AREA | timechart span=1d count(QP) by AREA limit=100 | addtotals
but this has been unsuccessful. QP is a number field. I need to show day by day the total by AREA.
Suggestions?
Thanks!
Have you just tried:
index=log sourcetype=data TYPE="PLATFORM" | timechart span=1d sum(QP) AS QTOTAL by AREA limit=100 | addtotals
?