|
When you have a timechart, by default you get the largest 10 values, then everything else bucketed into OTHER. Can anyone think of an effective way to get the smallest 10 (or X) in a timechart? What I have is KBps, and I want to find the values that have the worst performance over time. |
|
If you disable OTHER does that have the desired effect? Something like:
I believe that would show the 10 largest minimums. I thought of a hacky double search way... sourcetype=foo [search sourcetype=foo | stats avg(KBps) as avg by host | sort -avg | head 10 | fields + host] | timechart avg(KBps) by host but I was hoping for something more elegant.
(01 Dec '10, 01:32)
vbumgarner
|
|
Sure. The answer to this question takes you back to the old clunky syntax for changing how many split-by values would be shown. The old syntax to change from 10 hosts to 50 hosts was:
and this was of course later streamlined to :
but the old verbose syntax still works, and indeed can can do "bottom50":
|