I have a query similar to
index=beacon BeaconType=pageview | timechart span="1d" count by Country
giving
US CA FR
01 Jan 123 456 678
02 Jan 456 234 765
But I'd like it formatted like
Date Country Number
01 Jan US 123
01 Jan CA 456
01 Jan FR 678
02 Jan US 456
02 Jan CA 234
etc
Is this possible? (excuse the bad formatting!)
Thanks
you could try something like:
index=beacon BeaconType=pageview | bucket _time span=1d | stats count by _time Country | rename count AS Number
This will split the results into timely buckets of 1day and then count the number split by Country.
you could try something like:
index=beacon BeaconType=pageview | bucket _time span=1d | stats count by _time Country | rename count AS Number
This will split the results into timely buckets of 1day and then count the number split by Country.
Perfect, thanks a lot!