Expected stats result
Time every 5mins | Apps |count
1:00 |app1,app2,app3 |3
1:05 |app1,app4 |2
1:10 |app4 |1
Perhaps:
<base search> | bin span=5min _time | stats values(app) AS Apps dc(app) AS count BY _time
That's assuming you want the distinct set and count of apps during that time.
Perhaps:
<base search> | bin span=5min _time | stats values(app) AS Apps dc(app) AS count BY _time
That's assuming you want the distinct set and count of apps during that time.