I want to hide peaks in timechart that do not exceed a certain threshold. I'm trying the below query but am not having much success.
earliest=-7d@d latest=now sourcetype="squid" clientip=x.x.x.x | bucket_time span=1h | timechart span=30m count by clientip usenull=f useother=f where count>18000
Try doing everything up to your timechart command, including its arguments, but instead of the "where", add the where as a separate search command, like this: | where count > 18000
. The result set that timechart creates (you can view it as a table, if you wish) is then filtered to consider only certain events. Note that this may leave gaps in the data set....