I feel like this should be a piece of cake with distinct count. I'd like to turn this into a more elegant search:
searchterms | bucket _time span=1m | stats count by punct,_time | join [searchterms | stats count by punct| stats sum(count) by punct]
It gets the count of each punct in a given minute along with the total count for that punct over the entire search range.
Try this
yoursearchhere
| bucket _time span=1m
| stats count as CountForMinute by punct, _time
| eventstats sum(CountForMinute) as CountForPunct by punct
Try this
yoursearchhere
| bucket _time span=1m
| stats count as CountForMinute by punct, _time
| eventstats sum(CountForMinute) as CountForPunct by punct
That makes more sense it looks to work now.
I fixed my typo - so the above answer should work now. I was being cute by giving names to the counts, and I outsmarted myself...
This only gives Count for minute strangely it does not seem that eventstats is doing anything