Often, we can use
eval(myField=someValue)) with aggregate functions like count and avg, as well as time function like per_day, to process matching events. Is there a way for eval to match all values (or equivalently, the existence) of a field? This would be useful for searches like:
timechart per_second(eval(status=*)) to no avail.
Thanks for the answer, but I believe the issue with using
count instead of
per_second (as in my original post) is that it depends on the span - I will get different answers if span=1h vs span=1min. Would you agree?
Sorry I tested count and only now tested per_second. The results are coherent though, any aggregation function works the same here.
Answering to your question, yes surely you'll get different results depending on your timespan, because granularity is changing. It is acceptable and somehow expected to produce different results