Hey guys ,
I need last 30 days stats for the use-cases that did not fire up on the ES console. Below is the query that i designed
`notable` | search NOT `suppression` | timechart usenull=f span=30d count by rule_name | where _time >= relative_time(now(),"-1mon")
But not getting the desired results as they are only populating one specific date into it. Can someone please refine the above query as i need the trend analysis for the usecases ?
in your timechart you are defined span=1mon => you will get only one time/date to _time field for all events. Then in where expression you are selecting events which have max one month old.
Probably you want to use eg. span=1d or something else to get more granularity to your results?