I'm interested in creating a threshold alert for bits/s or packets/s of my data. This is leading me down a rabbit hole, and it seems like doing any analysis (sorting/aggregation) on this kind of per second data is quite difficult; the only option seems to be to use the TSVB and create a visual with that.
I considered using data transforms to try and do things by "entity" but I can't figure out how to exactly do that given that I need the per second rates for a given source.ip. I'm using data in the ECS format so I have fields like network.bytes or network.packets.
Any suggestions on being able to do more interesting manipulations of data that is per second?