index=*** sourcetype=*******
| bin _time span=1d
| rex "\[Id=(?[^\,]*?),[\s ].*?,[\s ]score=(?[^\,]*?),[\s ].*?,[\s ]location=(?[^\,]*?)," max_match=0
| streamstats avg(scoreValue) AS avgpred, stdevp(scoreValue) AS lstdev , var(scoreValue) AS varpf by locationValue,IdValue, _time
| eval lowBound=avgpred-lstdev
| eval difference = if(scoreValue<lowBound,1,0)
| streamstats min(lowBound) as lowerBound min(difference) as diff by locationValue,IdValue, _time
| table _time locationValue IdValue lowerBound diff avgpred lstdev
... View more