I have a log in the following format:
username=nan time=09:00 operation=login username=ver time=10:00 opertiaon=logout username=ves time=09:00 operation=login username=ves time=10:00 opetaion=logout
I need the output in the following format as a scatter plot. I am able to make it in a table, but not in scatter chart.
Why not try something like this?
... | timechart count(eval(operation="login")) as logins, count(eval(operation="logout")) as logouts by username
Then chose a bar/column chart visualization?
Thanks for the response, but we have more than 30+ users and 5 to 6 operations , in that case the following solution gives
"These results may be truncated. Your search generated too much data for the current visualization configuration." notifaction