How to Chart Values in logs, not the number of logs

Comments

1 comment

  • Avatar
    Mario Sanchez
    Max, What you need to do is Sum your "a" field which contains your count of updates per message. Your query would look something link this: _sourceCategory=my_logs | parse "* updates are security updates." as a | sum(a) as total_updates Hope this helps. Cheers, Mario
    0
    Comment actions Permalink

Please sign in to leave a comment.