- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
use timechart with dedup values
kirrusk
Communicator
03-13-2020
09:56 PM
I'm trying to count values of field in a time chart with every particular point of time using dedup.
like this ,
index = internal field1 = asterisk field2 = asterisk field3 = asterisk | dedup field3 | time chart count(field3) by field2
but it is giving only total count of (field3) in a row. I want total count at every particular point of time to display in time chart.
sorry for typos
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

woodcock
Esteemed Legend
03-14-2020
12:59 PM
It is very unclear what you mean, what you need, and what the problem is. Perhaps you can get what you heed by taking some part of this:
index="internal" AND field1="*" AND field2="*" AND field3="*"
| timechart count dc(field3) BY field2
