You still need the timechart from your original search my query
| rex field=_raw "Time=(?<NewTime>\d{4}\.\d+)"
| eval TimeMilliseconds=(NewTime*1000)
| timechart span=1d count as total,
count(eva...
See more...
You still need the timechart from your original search my query
| rex field=_raw "Time=(?<NewTime>\d{4}\.\d+)"
| eval TimeMilliseconds=(NewTime*1000)
| timechart span=1d count as total,
count(eval(TimeMilliseconds<=1000)) as "<1sec",
count(eval(TimeMilliseconds>1000 AND TimeMilliseconds<=2000)) as "1sec-2sec"
count(eval(TimeMilliseconds>2000 AND TimeMilliseconds<=5000)) as "2sec-5sec"
count(eval(TimeMilliseconds>48000 )) as "48sec+", by msgsource
| untable _time msgsource count
| eval group=mvindex(split(msgsource,": "),0)
| eval msgsource=mvindex(split(msgsource,": "),1)
| eval _time=_time.":".msgsource
| xyseries _time group count
| eval msgsource=mvindex(split(_time,":"),1)
| eval _time=mvindex(split(_time,":"),0)
| table _time msgsource total *