Open
Description
Reference: #160321
I noticed a difference in log count between this chart and Log spikes analysis chart. Is this expected?
For this chart, criteria is passed as KQL and group by is passed as filter. In the Log spikes, we are passing everything as filter. Depending on the criteria, there can be different filter types - term
, match
, match_phrase
, range
which are used in rule executor. Do they provide same results as KQL generated for this chart?



Originally posted by @benakansara in #160321 (review)
Activity