index = "abcd" sourcetype = * Customers= ABC |chart count by Pages
I get the pages as a list
I want one of the page occurances with timeline
lets say page name is login.do so I want to know login.do happened at this particular time
There could be multiple events with one Pages, so which time you want, first time the page was access, last time page was accessed OR all accesses?
For All,
index = "abcd" sourcetype = * Customers= ABC Pages="login.do" | table Pages _time
For first and last time it was accessed
index = "abcd" sourcetype = * Customers= ABC Pages="login.do" | stats min(_time) as FirstTime max(_time) as LastTime by Pages | convert ctime(*Time)
index = "abcd" sourcetype = * Customers= ABC |timechart count by Pages
you're probably looking at the statistics tab.. click on the Visualization tab