I have a search as follows
field_id="X" | eval b=len(_raw) | stats sum(b) as b | eval gb=round(b/1024/1024/1024,2) | eventstats avg(gb) as Avg
Which displays the average gb per each day for that particular search.
Now, how can I make to display average of each host for that particular search in a timechart?
If host is already a field then
| timechart max(Avg) by host
View solution in original post