I am new to splunk and want to create a dashboard with few widgets. The first widget I need is for "bargraph or a line graph for # of ERROR level logs per 5 minutes over the last " the default if time interval is not provided is 1 hour i.e. display data for last one hour.
Like this:
index="YouShouldAlwaysSpecifyAnIndex" AND sourcetype="AndSourcetypeToo" AND log_level="ERROR"
| timechart count span=5m BY host
Check out the timechart
command. link to docs
If you're new to splunk I would also recommend the splunk fundamentals course