Hi @myte , as you like! but scheduling the two searches: |.... main search...
| bucket _time span=1h
| stats count BY _time
| stats
avg(count) AS AverageCount
max(count) AS MaxCount
| eval
AverageCount=round(AverageCount,2),
MaxCount=round(MaxCount,2),
Type="Per Hour"
| collect index=my_summary and |.... main search...
| bucket _time span=1m
| stats count BY _time
| stats
avg(count) AS AverageCount
max(count) AS MaxCount
| eval
AverageCount=round(AverageCount,2),
MaxCount=round(MaxCount,2),
Type="Per Minute"
| stats
values(AverageCount) AS AverageCount
values(MaxCount) AS MaxCount
BY Type
| collect index=my_summary and running this search when you need resuts index=my_summary
| table Type AverageCount MaxCount you have the same result in a single search and a quicker search. let us know if you need more help, and, for the other people of Community, please, accept one answer. Ciao. Giuseppe P.S.: Karma Points are appreciated by al the Contributors 😉
... View more