Unfortunalety your example does not work for me.
Maybe I do not correctly interpret it.
source="websample.log" | timechart sum(count) AS < status="202" status="404" > by status
... View more
The ePub (iPad, etc) version is available now, for free at http://splunkbook.com
The hard copy should be available in about 2 weeks at Amazon.
... View more