How to make charts with derived fields
I have a simple query which gives me a single value.
json auto keys "message"
| parse "view [*] bus [*]" as receivedEvents, filteredEvents
| sum(receivedEvents) as received, sum(filteredEvents) as filtered
| received - filtered as totalFiltered
| fields totalFiltered
I need to make a timecourse line chart.
I tried adding timeslice 1h then sum(totalFiltered), but that is bad ssyntax.
json auto keys "message"
| parse "view [*] bus [*]" as receivedEvents, filteredEvents
| sum(receivedEvents) as received, sum(filteredEvents) as filtered
| received - filtered as totalFiltered
| timeslice 1h
| sum( totalFiltered ) by _timeslice
I tried several wrong variations on this, but I don't know how to get the line chart I want.
Please sign in to leave a comment.
Comments
1 comment