I want to calculate the ratio of two counts, per minute, over a longer period. I can do this in timelion easily
But I'm stuck on how I can generate a query to display this data.
I can get a data histogram for *, and a date histogram for "myquery", but I'm stuck on getting ES to do the arithmetic for me. Is this even possible?
The use case: I monitor this ratio (2* or 3* response codes as a portion of total hits, in web logs) in realtime by pulling a single value for each filter for the timestamp lte now and gte now-1m and dividing one by t'other. I now want to pull historical data.
I have a weird feeling that significant terms agg with the percentage heuristic could do this under certain bizarre conditions: after all, it's not so different to comparing a filtered value against a background count, within a date histogram agg. But maybe I'm way off.