Hi all,
Having developed a filter that dials in the events and fields I want, I'd now like to have it display only events in which a unique user exceeds X matching events within Y timeframe.
I've deduced that a combination of top/associate/chart is probably where I need to go, but I can't quite put them together.
Any hints from the common collective?
Thank you!
How about this:
... earliest=-15m@m latest=now | stats count by user | where count > 20
Very help, thank you!
How about this:
... earliest=-15m@m latest=now | stats count by user | where count > 20