Is it possible to
index="myindex" mcType=auditLog | search auditType="*" | stats count by auditType | where count (This is where I don't know what to do)
Is it possible to show where count has increased by 10 percent from the average of the last 12 months.?
Hi,
You are probably looking for something like filter days where count >10% of yearly average.
Try this query as it is, I wrote it on the _audit index so that it works for you as wellindex="_audit" | timechart span=1d count| eventstats avg(count) as avg | where count >=0.1*avg
You need to retro fit your index
What's time range you're using for your original query?
Hi,
You are probably looking for something like filter days where count >10% of yearly average.
Try this query as it is, I wrote it on the _audit index so that it works for you as wellindex="_audit" | timechart span=1d count| eventstats avg(count) as avg | where count >=0.1*avg
You need to retro fit your index
This is sort of what I'm looking for.
Is there a way to format the query so that it counts by audittype and displays the average next to it like you did for your index?
Like if I did
index="myindex" mcType=auditLog auditType="*" |stats count by auditType
It currently shows as
auditType , count
but I'd love to see
auditType , avg, count
With your query index="myindex" mcType=auditLog auditType=* | timechart span=1d count| eventstats avg(count) as avg | where count >=0.1*avg
I'm getting time, count , average
index="myindex" mcType=auditLog auditType="*" |stats count by auditType|eventstats avg(count) as avg | where count >=0.1*avg | fields - avg
Thank you, this was very helpful to steer me in the right direction.