Hi Base,
I just run into a problem and I can´t solve it by my own. So, maybe someone here can bring me back on track:
I build a timechart of a windows sec log: …| timechart span=30m count(TaskCategory) by Accountname fine so far. Now I want to suppress all results f.e. which are less than 50 but how?
where count >50 won´t work.
Thanks!
This is somewhat tricky. Once the data has left timechart, the values are assigned to fields named by the values of "Accountname".
We have to preprocess the data and make sure that timechart doesn't get the undesired values to begin with.
... | bin span=30m _time
| stats count(TaskCategory) as TaskCategoryCount by _time, Accountname
| where TaskCategoryCount < 50
| timechart span=30m sum(TaskCategoryCount) as TaskCategoryCount by Accountname
This is somewhat tricky. Once the data has left timechart, the values are assigned to fields named by the values of "Accountname".
We have to preprocess the data and make sure that timechart doesn't get the undesired values to begin with.
... | bin span=30m _time
| stats count(TaskCategory) as TaskCategoryCount by _time, Accountname
| where TaskCategoryCount < 50
| timechart span=30m sum(TaskCategoryCount) as TaskCategoryCount by Accountname
Thanks! This works fine for me!