I am creating a dashboard with one panel displaying 404 errors. I am able to get this working fine with the following inline search, but I want to modify this so I only see the top 10 hosts as otherwise the majority of each bar ends up being "other".
"HTTP Status 404" OR "HTTP Status code: 404" minutesago=30 | timechart count AS Exceptions by host
When I try to modify it with a | top limit=10 host at the end of the inline search, I get no results.
Thanks
Have you tried:
"HTTP Status 404" OR "HTTP Status code: 404" minutesago=30 | timechart count AS Exceptions by limit=10 host useother=f
More information about timechart here:
http://www.splunk.com/base/Documentation/latest/SearchReference/Timechart
Travis.
Have you tried:
"HTTP Status 404" OR "HTTP Status code: 404" minutesago=30 | timechart count AS Exceptions by limit=10 host useother=f
More information about timechart here:
http://www.splunk.com/base/Documentation/latest/SearchReference/Timechart
Travis.
perfect! Thanks for the quick help. I guess I need to go read up on exactly what "useother" does.