Panel 1 Query - index=production sourcetype="db" (APPLICATIONTYPE="A" OR APPLICATIONTYPE="B" OR APPLICATIONTYPE="C" ) (ACCOUNT="$ACCOUNT$", REQUEST="$REQUEST$",STATUS_DETAIL="$STATUS_DETAIL$",STATUS_TYPE="$STATUS$") | eventstats sum(RECORD_COUNT) as TOTAL_COUNT by ACCOUNT, REQUEST,STATUS_DETAIL,STATUS | eval account_request_status = ACCOUNT . ":::" . REQUEST . ":::" . STATUS | timechart span=1m limit=0 sum(RECORD_COUNT) by account_request_status Panel 2 Query - index=production sourcetype="db" (APPLICATIONTYPE="A" OR APPLICATIONTYPE="B" OR APPLICATIONTYPE="C" ) $requesttype$ $Account$ $status$|eventstats sum(RECORD_COUNT) as TOTAL_COUNT by REQUEST ,ACCOUNT,STATUS_DETAIL, STATUS | stats count by ACCOUNT, REQUEST,STATUS,STATUS_DETAIL, TOTAL_COUNT | fields - count STATUS_DETAIL is generating regex which is generated in realtime. Please help.
... View more