@WXY,
Try
(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype
Hi WXY
try
(index=interface sourcetype="in_t") OR (index=imp sourcetype="out_t")
| timechart count
Bye.
Giuseppe
@WXY,
Try
(index=interface OR index=imp) (sourcetype="in_t" OR sourcetype="out_t")|timechart count by sourcetype