Does stats support function inside function like shown below ?
Where first i want to take percentile90 of PERCENT90 field value and then sum it up by function as shown below in query
search........... | eval PERCENT90=round(PERCENT90,2) | eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S") | stats DC(DAY) as DayCount **sum(Perc90(PERCENT90))** by FUNCTION
I am trying to get the below result
search........ | rex field=source "APP_(?.*)" | eval PERCENT90=round(PERCENT90,2) | eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S") | stats **Perc90**(PERCENT90) as **record** | stats DC(DAY) as DayCount **sum(record)** as SUMA by FUNCTION
so I want to pass the percentile90 calculation done from first stats to next stats sum()
try changing | stats perc90(PERCENT90)
to | eventstats perc90(PERCENT90)