I've got a very basic query which computes an average of some daily attempts to do something like this:
index=monitoring | timechart span=1d sum(done) as Success sum(try) as Attempt | eval Percent=round(Success*100/Attempt,2) | convert ctime(_time) as Date timeformat="%d %B" | fields - _time | fields Date Percent
I'm unclear how I could find the day with the highest value of "Percent" over a month's worth of daily valules. Would I need to create a summary index to handle this?
No summary index needed for this - try this instead
index=monitoring | eval Date =strftime(_time,"%d %B" ) |
stats sum(done) as Success sum(try) as Attempt by Date |
eval Percent=round(Success*100/Attempt,2) |
eventstats max(Percent) as maxPercent |
where Percent = maxPercent |
fields - maxPercent