In SumoLogic we created a visualization that took an average of all the execution times and filtered out the top 10%, so you could see a truer average of processtime rather than a couple of outliers creating spikes. The where part of our query looked like -
| pct(executiontime,90) by _timeslice, processtype
I can't figure out how to get the same results in Kibana. Any thoughts?