EventID = “ok”
| timechart span=1h count(EventID) by Login
Every hour I need to display only those values, where count(EventID)>5
I have used filter command (where) after timechart command but it didnt worked.
Please help me!
Thanks in advance!
Not a clean solution but this should work
EventID="ok" | bin span=1h _time | stats count(EventID) as cnt by Login _time | where cnt > 500 | timechart span=1h sum(cnt) as cnt by Login| fillnull value=0
Not a clean solution but this should work
EventID="ok" | bin span=1h _time | stats count(EventID) as cnt by Login _time | where cnt > 500 | timechart span=1h sum(cnt) as cnt by Login| fillnull value=0