Hi There,
I have a search that shows the top 2 Id's that have the most payments processed in each country. I'm trying to make this search give me these results per hour
The search itself works as expected in the below format, I just want to give the results in an hourly interval instead
`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| top limit=2 id by country, status
I've tried putting it into a timechart and also using the span but it keeps asking for a function and I don't know how to rewrite the above into hourly spans.
This may help...
`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| bin span=1h _time
| top 2 id by _time country status
This may help...
`index` "Payment Status"
| rex "status:(?P<status>APPROVED|DECLINED)"
| search status=APPROVED OR status=DECLINED
| bin span=1h _time
| top 2 id by _time country status