Hi,
I have a search that looks kinda like this:
host=host1 OR host=host2 AND (errcode=E OR errcode=R) | dedup punct
when i run this for Thursday the 24th - i get 22 results.
However, when i add | timechart count , that day, it counts only 1 entry.. so if i click on the bar for that day, which says it counts 1 - the search that pops up has 22 entries!
I don't know what i'm doing wrong, but i suspect it's not counting the right thing.. i did try count(_raw) but that did not change anything, still got 1 in the report and 22 results for the search.
Thank you very much,
Oleg
... View more