Dumb question I cannot find a simple answer to. 🤣
If I run a simple timechart search for 7 days, 30 days or 90 days --
How can I overlay the 7 day, 30 day or 90 day average line over the timechart?
For example:
index=blah sourcetype=blah filter_term=blah
| timechart span=1d count as daily_count
Add this to the end
| eventstats avg(daily_count) as average
Thank you sir
and if you have a split by clause and you want an average of the total for a day, then use
| addtotals
| eventstats avg(Total) as average
| fields - Total