Graylog2 / Graylog2/graylog2-server
Line Chart by Timestamp Row Uncommon Events(Bottom)
- Dominant language
- Java
- Stars
- 8.1k
- Forks
- 1.1k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 217
Description
## What?
I can make Line chart by time flow(timestamp) and "count()" metric. That draw lines to me with TOP+ Events Like in this screenshot:

But I want to monitor and visualize the TOP- (Bottom) Events, or The events that apear less in my system. I Tried several parameters and metrics but can't do it.
## Why?
I think this feature is pretty helpful to monitor the less common event OR a silent attack.
## Your Environment
* Graylog Version: 4.0.1
* Elasticsearch Version: 7.9.3
* MongoDB Version: 4.2
* Operating System: FreeBSD 12.1
Contributor guide
Assessment
This issue has not been assessed yet.