You have the correct line of thinking. There is a custom field extraction, TemperatureA , that exists for when there are multiple <Reading> nodes.
If it helps, the search criteria I have created already is:
host="Jetstream" AND sourcetype="SensorReadingEvent" AND LogicalDeviceId="10000452" | dedup EventId | <rest of search>
When I add in your first suggestion, it gives me the results in a Results Table. However, instead of the _time factor just being say hourly, it is broken up into 30 minute intervals. This leaves gaps in the resulting max(temp) column.
For me the ideal would be a time column based on the ReadingTime key/value and a second column for TemperatureA . It would be a one for one listing and not a summary. However, I'm not sure the charting allows for direct input like that. Hopefully that makes sense.
As for the data source, its more for system monitoring of devices. I'm attempting to create a Device-centric view/dashboard for quick assimilation of data the device is reporting.
... View more