Hey @PickleRick I like that approach - hadnt thought of the subsearch in the timechart to achieve so bookmarking that for future ref Not to be pedantic....I'd probably go for <90000=1h instead...
See more...
Hey @PickleRick I like that approach - hadnt thought of the subsearch in the timechart to achieve so bookmarking that for future ref Not to be pedantic....I'd probably go for <90000=1h instead of <86400 because if you select "Last 24 hours" then you get slightly more than 24 hours (something like 31-03-2025 22:00:00 to 01-04-2025 22:09:12) @tkwaller1 if you want to get a single value out of it then you could do something like the below - Ive added an appendcols to add the span info into a field so people know what its an average of. index=_internal
| timechart
[| makeresults
| addinfo
| eval range=info_max_time-info_min_time
| eval span=case(range<60,"1s",range<3600,"1m",range<90000,"1h",1=1,"1d")
| eval search="span=\"".span."\""
| table search ] count partial=f
| stats avg(count) as avgCount
| appendcols
[| makeresults
| addinfo
| eval range=info_max_time-info_min_time
| eval span="per ".case(range<60,"1s",range<3600,"1m",range<90000,"1h",1=1,"1d")
| table span ] Did this answer help you? If so, please consider: Adding kudos to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing.