Hi There,
I have got some results in after running the below command
my search |
| bucket _time span=1h
| stats count by _time http_status
| eventstats sum(count) as totalCount by _time
| eval percent=round((count/totalCount),3)*100
| fields - count - totalCount
Output is as follows
time status percent
2022-03-02 05:30:00 | 100 | 10.0 |
2022-03-02 05:30:00 | 200 | 30.0 |
2022-03-02 05:30:00 | 300 | 60.0 |
2022-03-02 06:30:00 | 100 | 30.0 |
2022-03-02 06:30:00 | 200 | 60.0 |
2022-03-02 07:30:00 | 300 | 10.0 |
2022-03-02 07:30:00 | 100 | 20.0 |
2022-03-02 07:30:00 | 200 | 30.0 |
2022-03-02 06:30:00 | 300 | 50.0 |
I am trying to transpose the output as below :
time 100 200 300
2022-03-02 05:30:00 | 10.0 | 30.0 | 60.0 |
2022-03-02 06:30:00 | 30.0 | 60.0 | 10.0 |
2022-03-02 07:30:00 | 20.0 | 30.0 | 50.0 |
please assist
@ITWhisperer thank you so much, it worked as expected
| xyseries time status percent