So I want to create a dashboard with each panel monitoring one index. Within a panel, it would be a timechart with count by time and each sourcetype would be represented by a separate line.
Here's a mockup of what I wanted to achieve:
I know it's pretty. Now the catch is - normal searches are gonna be very resource intensive and I'd rather have something lightweight if possible.
Any suggestions would be appreciated - I tried tstats but wasn't able to make it work in that manner.
Cheers!
If you're just looking to plot event count by index and sourcetype, tstats would be the fastest way. Try like this
| tstats count WHERE index=YourIndex by _time sourcetype span=1d | timechart span=1d max(count) as count by sourcetype limit=0
If you're just looking to plot event count by index and sourcetype, tstats would be the fastest way. Try like this
| tstats count WHERE index=YourIndex by _time sourcetype span=1d | timechart span=1d max(count) as count by sourcetype limit=0
Thanks @somesoni2, that's exacly what I was looking for!