Hello Everyone,
I have a query where a user selects a time range in the timeticker
Let say 10 november 08:30am to 10 novemeber 11:30am
The user wants to only see the events for the last 5 minutes
i.e from 10 novmeber 11:25am 10 novemeber 11:30am to look for errors in that 5 minutes
He has two panels
I'm able to create panel 1 how to create panel 2 how
Below search for panel 2
earliest=-5m latest=$info_max_time$ index=newdata sourcetype=oracle source="/u0/DATA_COUNT.txt" loglevel="ERROR" |bin span=5m _time |stats dc(loglevel) by INSTANCE_NAME
Try something like this for 2
index=newdata sourcetype=oracle source="/u0/DATA_COUNT.txt" loglevel="ERROR"
[| makeresults
| addinfo
| eval earliest=relative_time(info_max_time,"-5m")
| eval latest=info_max_time
| table earliest latest]
| stats dc(loglevel) by INSTANCE_NAME