HI there,
I was hoping someone may have some advice on how to plot a graph for the following trend,
I am trying to figure out, how to graph the value increase and decrease for the instances of Media files count: 634144. e.g. you will see below that the count, changes over time. I want to do a time chart portraying these values, changing over time, against the source types, these entries belong to. Thanks for any ideas?
2013.02.10 20:56:46:199 INFO avidmi 2608 nycoewg01mi02 CACHE SAVED. Media files count: 634144. Unique media files count: 625887. Duplicated media files count:8257 215
2013.02.11 12:56:48:192 INFO avidmi 2608 nycoewg01mi02 CACHE SAVED. Media files count: 629238. Unique media files count: 621189. Duplicated media files count:8049 215
2013.02.11 14:56:48:392 INFO avidmi 2608 nycoewg01mi02 CACHE SAVED. Media files count: 632638. Unique media files count: 624586. Duplicated media files count:8052 215
thanks - that worked perfectly - I am using it all the time now....
You are welcome.
For other splunk magic functions, take a look at the cheat sheet http://www.innovato.com/splunk/
also if you do not mind, please accept the previous answer with the transparent check mark on the left side.
Excellent - thanks very much. Just what i needed.
Extract the value in a field, using rex or an automatic field extraction.
beware the "Media" caps is important, because you have almost he same 2 times.
... |rex "Media files count: (?<media_files_count>\d+)" | table _time media_files_count sourcetype
then use it for a timechart
... |rex "Media files count: (?<media_files_count>\d+)" | timechart span=5m avg(media_files_count) by sourcetype