Trying to sort by highest URL count, limit to 12(prevent "other" in the time-chart) and then time-chart. Thanks!
This doesn't seem to give me the desired results:
... | streamstats count by URL | accum URL | sort count limit=12 | timechart count span=2m by URL
Another thing worth mentioning when i remove 'accum URL' and replace sort with | where count > n | it works but is not an automatic solution... I guess with "sort" i have to worry about rows being created and if >10000 rows are created i will have truncated results. Is that accurate?
This is what i'm using currently and it seems to be working -
... | streamstats count by URL | where count > 10 | timechart count span=2m by URL
Is stream stats counting by the search duration? If i choose 2 hours it will look for any urls counts > 10 over 2 hours? or is it looking at a smaller default bucket size if i do not specify it prior?