Samples the event stream. Events that do not have the field being sampled are discarded.

ParameterTypeRequiredDefault ValueDescription
fieldstringoptional[a]@timestamp The names of the field to use for sampling events.
percentage[b]doubleoptional[a]1 Keep this percentage of the events.
   Valid Values
  Maximum100 
   1

[a] Optional parameters use their default value unless explicitly set.

[b] The argument name percentage can be omitted.

Hide omitted argument names for this function

Show omitted argument names for this function

sample() Examples

Sample events keeping only 2% of the events

logscale
sample(percentage=2)

Sample events keeping only 0.1% of the events to allow groupby to find the most common hosts without hitting the groupby-limit:

logscale
sample(percentage=0.1)
| groupby(host)
| sort()