Sep 20 2017
- last edited on
Apr 07 2022
Following the multiple dimensions documentation example it says
Multiple expressions in the by clause creates multiple rows, one for each combination of values.
I want to query their sample database for networks bytes Send and Received per each computer. Starting with this query it should be something like
Perf | where TimeGenerated > ago(1d) | where (CounterName == "Bytes Received/sec" or CounterName == "Bytes Sent/sec") | summarize avg(CounterValue) by bin(TimeGenerated, 1h), Computer, CounterName | extend Threshold = 20 | render timechart
The problem is that Send and Received bytes gets grouped in the graph at computer level which doesn't make any sense.
How can multiple dimensions be represented as stated in the documentation so that I have Computer X Bytes Send and Computer X Bytes Received. As a note this was perfectly doable in the previous version.
Sep 20 2017 04:41 AM - edited Sep 20 2017 04:41 AM
Not as clean as I would like but I have figured out that a string concatenation would do the trick