I have a query showing all errors of interest. Excerpt of result:
When this error happens, we get 3-6 errors spit out within milliseconds of each other, so what I'd like to do is take this search result and get a nice chart of the number of events, grouping all events from the same failure windows together. All 3 shown in the image would be counted as one.
My line of inquiry has resulted in:
**query** | timechart count by (date_month AND date_mday AND date_hour AND date_minute)
but that is still resulting in a count of 3 for the events in my image. Suggestions?
Try like this
**query** | timechart dc(date_second) as ErrorCount
Do you have different error messages and want to count different Error messages within same second separately. If yes, then try like this
**query** | eval err=date_second."#".Error_Field | timechart dc(err) as ErrorCount