Dahsboard pannel with log entires

Comments

1 comment

  • Official comment
    Avatar
    Matt Sullivan

    Hi Justin,

    Sorry for the delay, hope this is still useful.  Dashboard panels can only be made from queries that use aggregate operators.
    Below would I think do what you require:

    // your query scope goes here
    // presuming too you parsed out type and message

    | formatDate(_messagetime, "MM/dd/yy HH:mm") as %"date/time"
    | count %"date/time", type, message
    | fields - _count


    Note that if you really meant to show the entire message in that column, add this code below scoping portion:
    | _raw as message 

    Regards,

    Matt

Please sign in to leave a comment.