Hi,
I need to plot time difference between consecutive events by sourcetype in the last 7 days.
I'm using this search but it's slow for a dashboard
index=myindex sourcetype=(sourcetype1, sourcetype,sourcetype3)
| streamstats windwos=2 global=f range(_time) as delta by sourcetype
| timechart max(range) as "delta [sec]" by sourcetype
do you have any suggestion for a more efficient search?
Thank you,
Marta
You could try using metasearch since you are only really dealing with meta-data
Another possibility is to schedule a regular report to save this data to a summary index and use the summary index for your dashboard
Or do both of these.
The caveat to summary indexes, is that you might want to ensure that your reports are overlapping so that you don't miss an interval but also make the updates idempotent so you don't end up double counting.