我想显示每个时间片的最小值、最大值以及最大值和最小值之间的差的图表。它适用于最小值和最大值
| parse "FromPosition *)" as FromPosition
| timeslice 2h
| max(FromPosition) ,min(FromPosition) group by _timeslice
但我找不到指定差异的正确方法。例如
| (max(FromPosition)- min(FromPosition)) as diffFromPosition by _timeslice
返回错误 - 发现意外的令牌“b”。
按照https://help.sumologic.com/05Search/Search-Query-Language/aaGroup上的建议,我尝试了几种不同的组合来在不同的行上声明它们。例如
| int(FromPosition) as intFromPosition
| max(intFromPosition) as maxFromPosition , min(intFromPosition) as minFromPosition
| (maxFromPosition - minFromPosition) as diffFromPosition
| diffFromPosition by _timeslice
没有成功。
谁能建议正确的语法?