I'm having trouble writing a query which displays the action and host count where log count is below average on any host.
The output would look something like this:
action | host1 | host2 | host3 | host4 | host5 | host6 |
getdata | 23404 | 22600 | 22592 | 88 | 22512 | 22244 |
hi @kgaurav ,
Try this:
index=index
| stats count by action, host
| eventstats avg(count) as avg by action
| eval count=if(count>=avg, count, "(".count.")")
| fields action, host, count
| xyseries action, host, count
If this reply helps you, an upvote/like would be appreciated.