| metasearch index="l-hhvm" OR index="l-nginx"
| timechart count as event span=1month by index
| eventstats max(event) as event_count by _time index I want to get a time based understanding of when these indices have event data, over all time. But, there is way too many events to count all the way up to the total per month. I would be happy to just count to 10000 and move on to the next month. Ideally, count for each month, for each index, up to 10000 (to represent significant data present) all time (could be up to two years). Sampling won't work becuase there are too many events, it would still take too much time. what i'm currently getting, would be good to keep this formatting
... View more