In my logs, I capture application errors and the log includes the application version. I have figured out with the search below how to get a daily average of all errors logged by any version:
<My Query for Error Condition>
| bucket _time span=1d
| stats count by _time
| stats avg(count) as AverageCountPerDay
This gives me a single value of average logged errors. What I want to do next is have a table output, listing the average errors for each of the version values in my Application. Instead of a single value for all the output, I would have multiple rows with the columns: Version and Avg Daily Errors
Hi epsplnkusr,
If you can parse out the version #, you could do something like..
... | stats avg(count) by version | rename avg(count) as "AverageCountPerDay"