I have a problem using the timechart command with this query. if i use "table" it works, but with timechart it doesn't... anybody can help?
|host..., source..., etc
| table AREA, SUBID, CURRENT_TIMESTAMP
| join AREA, SUBID, CURRENT_TIMESTAMP
[|search source... EVENT_TYPE...
| table AREA, SUBID, TXT, CURRENT_TIMESTAMP ]
| eval message_id=AREA.SUBID." ".TXT
| timechart count(message_id) as "No. of message" by message_id
Hi @Goldenfit,
timechart command works only if you have the _time fields.
But you haven't this field.
You could use the stats command using CURRENT_TIMESTAMP as grouping BY option.
In addition, join is a command to use only when you haven't any other solution and having few events, otherwise it's a very slow command; I hint to you to re-design your search using stats.
Ciao.
Giuseppe