@rajhemant26,
If you just want the count for last 2 minutes, set the earliest time to last 2 minutes relative to current time and do a stats count on the data,
For eg.
host=werdw* sourcetype=dfgc_metric R=* earliest=-2m@m
| eval host_type=case(host LIKE "%wap%", "WAP", host LIKE "%web%", "WEB", host LIKE "%task%", "TASK",
host LIKE "%iin%", "IIN", host LIKE "%gen%", "GEN", host LIKE "%ion%","ION",
host LIKE "%int%", "INT", host LIKE "%out%", "OUT", host LIKE "%rpt%", "RPT",
host LIKE "%rpo%", "RPO", 1=1, "Other")
| stats count as Request by host_type
You need to use bin/bucket only if you want to split the data into time bukcet of 2 mins for the last x minutes/hours.
streamstats is used when you need a moving sum/avg/otehr agg functions over data
... View more