So if I have over the past 30 days various counts per day I want to display the following in a stats table showing the distribution of counts per bucket. IS this possible?
MY search is this
host="foo*" source="blah" some tag
host [ 0 - 200 ] [201 - 400] [401-600] [601 - 800 ] [801-1000]
X 0 10 15 4 1
Y 1 9 13 6 1
Z 5 6 10 5 4
Thanks in advance!
You're probably looking for something like this:
... | bin span=1d _time | stats count as temp by _time host
| bin span=200 temp | chart count by host temp
You're probably looking for something like this:
... | bin span=1d _time | stats count as temp by _time host
| bin span=200 temp | chart count by host temp