I'm using (transaction) to count the number of events in a stream of data.
There are numerous single events, but I'm only interested in events that are 2 or more.
Using the string maxevent=X, I can limit the maximum number of events within a given time span,
but can you ignore a number of events less than a given number (ie: minevents=2)???
index=generic | transaction data maxevents=2 maxspan=2m
Any transaction command adds fields like duration and eventcount. You can filter based on field eventcount.
index=generic | transaction data maxspan=2m | where eventcount > 1
Any transaction command adds fields like duration and eventcount. You can filter based on field eventcount.
index=generic | transaction data maxspan=2m | where eventcount > 1
Good idea. Thanks. 🙂