Hi, I need to get the no.of events happened over last 90 days, 60 days, 30 days in one column chart. Using eval, if. Use the if command to group the events by their time stamps.
search
| bin _time span=30d
| stats count by _time
hey how can i get the no.of events between 30 days and 60 days
By using the bin command, the _time is set to the begging of the 30day period, so 30 day count will be the most recent count and 60 will be the previous count