I have use sort event from big to small ,now i want to sum 1-30,31-100,101-500,501-3000,3000- .how to do it ? thanks in advance.
Thanks ,vbumgarner!
Something like this should do it:
* | top limit=100 foo | eval a=1 | accum a | rangemap field=a 1-30=1-30 31-100=31-100 101-500=101-500 501-3000=501-3000 default=large | stats sum(count) by range