Hi all,
whenever I get a new log I wanted to count of the number of logs for the last 5 min and then append it to a graph. but I should be able to see graph of 1whole day
Perhaps something like this?
| timechart span=5m distinct_count(source)
actually I need to do a real time search and append the results to a graph continuously.
That's what should happen using the above.
that's correct but its creating something like buckets of 10min each like 2:00 to 2:10 and then counting in that time range.
but what I need is as soon as I get data lets say at 2:14 it should count the data from 2:04 to 2:14 and then append the count to graph.
when I get new data at 2:16 again it should count from 2:06 to 2:16 and append the count to graph again.