I'm using the following query to create a stacked bar chart:
* | keyvalue auto
| timeslice 1h
| count by _timeslice, queryperformed
| transpose row _timeslice column queryperformed as *
The timeslice here is bound to the time sumo received the log message.
How can I use a date that is included in the log message rather than the receipt date?
Please sign in to leave a comment.