I have transactions with varying number of events. I want a plot showing how many events occur in buckets since the beginning of the transaction, e.g. how many events in the first 5 seconds, next 5 seconds, etc.
How can I do this?
Lets assume you transactions are grouped by a txn_id. See if this is what you're looking for...
index=foo sourcetype=bar | bin span=5s _time | stats count by txn_id _time
thanks sundareshr, it doesn't quite work, there are many transactions starting at different times