I have a search that get code values:
How can I show only the count of 4 values in a chart and have the rest reported as "OTHER".
... | top 4 yourfield useother=t
One more twist. How do I show this in a time chart?
Ah, that's a bit trickier. This is the solution I can think of right now - possibly there's a 'neater' solution, but if there is one I'll have to sleep on it. 🙂
... | stats count(eval(yourfield=="value1")) as value1, count(eval(yourfield=="value2")) as value2, count(eval(yourfield=="value3")) as value3, count(eval(yourfield=="value4")) as value4, count(eval(match(yourfield,"value1|value2|value3|value4"))) as OTHER | transpose
Thanks, Ayn.
That works if I want the top 4 values. I forgot to mention that the 4 values I want will not necessarily by the top 4 by count.