I want to create a time series chart to simply plot the number of events SumoLogic is ingesting by a host. The x axis should be time and the y axis should be the number of events. There would be a line for each hosts.
I have parsed out the host as "aHost". Not really sure how to plot it across time.
| parse regex "^\w+\s+\d+\s\d+:\d+:\d+\s(?<aHost>\w+-\w+-\w+-\w+-\w+)"
| timeslice by 5m
| count_distinct(_raw) by aHost
Please sign in to leave a comment.