- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to make a timechart/graph from a search result?
I have some events with message
field as Bar Hello..
, Bar Hi...
, Bar Foo...
and so on. I do not know beforehand how many this type of message
are there. It is purely dynamical. But this messages are generated one at a time and timestamp of events with this messages are different. Now I want to show the search results as timechart
. Right now I have this
index=baz host=server1 message="Bar*" | table host message _time | sort by -_time
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You should just need the timechart command.
See Below:
index=baz host=server1 message="Bar*" |timechart count(message) by message usenull=f useother=f
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It would be good if in the graph it is a single line with different color for different type of message.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Not sure how that would work. A single line for x number of message types won't work as a visualization. you could do a Stacked column Chart view instead of a line chart. Above should produce multiple lines each a different color and one line for each message type over time.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you wanting to know how many of the messages you are receiving for a given timeframe?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No I don't want to know how many but I want to create a line chart based on the messages and their frequency. Though I think I got close to it index=baz host=server1 message="Bar*" | table host message _time | sort by -_time | timechart span=2m count by message usenull=f
. Now it would be good if in the graph it is a single line with different color for different type of message.
