Within our application we are tracking a "Pings" metric, and in our query we are showing pings over time along with a metric called "instances" that's calculated in real-time by dividing "Pings" by 24:
index="helloworld" metric="ping" | timechart count as Pings span=1d | eval Instances=floor(Pings/24)
This query has the result of showing both "Pings" and "Instances" in the timechart. How can we only display "Instances" and remove the "Pings" line?
Just remove it with the fields command at the end of your search.
... | fields - Pings
That should remove "Pings" but leave all else.
Just remove it with the fields command at the end of your search.
... | fields - Pings
That should remove "Pings" but leave all else.