I have the below search which shows 3 columns....the field1, index list and count of events. How can I add a trend line or a spark line to show if the event count is increasing or decreasing.
| tstats count by index
| join index type=inner
| inputlookup LookUp1
| eval index=lower(index)
| table field1,index,count
| sort field1 asc]
| stats list(index) as index, sum(count) as count by field1
For a sparkline try:
| tstats count by index
| join index type=inner
[| inputlookup LookUp1
| eval index=lower(index)
| table field1,index,count
| sort field1 asc]
| stats list(index) as index, sum(count) as count, sparkline(sum(count)) as trend by field1
Let me know if that helps.
Philip
I tried this before but for the sparkline it shows a flat line with 0 value all across.