I want to create a Bar chart with the logs where the key would be the stats count field name and value would be the sum value
Query :
search1 | eval has_error = if(match(_raw, "WARNING"),1,0)| stats sum(has_error) as field1| join instance [search2 | eval has_error = if(match(_raw, "WARNING"),1,0)| stats sum(has_error) as field2| join instance [search3 | eval has_error = if(match(_raw, "WARNING"),1,0)| stats sum(has_error) as field3|join instance [search4 | eval has_error = if(match(_raw, "WARNING"),1,0)| stats sum(has_error) as field4]]] | stats sum( field1), sum(field2), sum( field3), sum( field4)
Current result:
field1
field2
field3
field4
30
44
122
6
Expected result:
Field
Count
field1
30
field2
44
field3
122
field4
6
... View more