I want to create a timechart that shows the amount of events per hour in the last 24 hours,
and a line in it that shows the average events per hour of the last 5 days. So far I'm stuck with this:
index=test ACTION=RECEIVE | eval events=1 | timechart span=1h sum(events)
How can I calculate the average events per hour of the last n-days and add it in that chart?
Any help is highly appreciated!
May be it is not optimal query but hope help you solve your task
index=test ACTION=RECEIVE earliest=-24h | eval events=1 | timechart span=1h sum(events) as T | eval tempfield="fieldforjoin"
| join tempfield [search index=test ACTION=RECEIVE earliest=-5d | eval events=1 | stats count(events) as Counthourmday by datehour datemday
| stats avg( Counthourmday) as avgevents | eval tempfield="fieldforjoin" ]
View solution in original post