Hi All,
I'm trying to create correlate events that have taken place on specific times/dates.
As an example:
Our base search is the below but we're wondering if we can build on this (or if there is a better approach)
sourcetype=ServiceSource EventTime="01.09.2013 10:0*" [search sourcetype=ServiceSource EventTime="25.08.2013 09:4*" | top limit=10 ComputerName | fields + ComputerName] | top limit=10 ComputerName
Thanks in advance.
For running a search on two distinct time ranges you could do something like this (on _internal for executability everywhere):
| stats count | fields - count | eval earliest = strptime("2013-11-11 11:11:11", "%Y-%m-%d %H:%M:%S").";".strptime("2013-11-12 12:12:12", "%Y-%m-%d %H:%M:%S") | makemv delim=";" earliest | mvexpand earliest | eval latest=earliest+600 | map search="search earliest=$earliest$ latest=$latest$ index=_internal | bin _time span=1d | stats count by _time host"
Starting from that, you could do analysis based on most chatty hosts.
For running a search on two distinct time ranges you could do something like this (on _internal for executability everywhere):
| stats count | fields - count | eval earliest = strptime("2013-11-11 11:11:11", "%Y-%m-%d %H:%M:%S").";".strptime("2013-11-12 12:12:12", "%Y-%m-%d %H:%M:%S") | makemv delim=";" earliest | mvexpand earliest | eval latest=earliest+600 | map search="search earliest=$earliest$ latest=$latest$ index=_internal | bin _time span=1d | stats count by _time host"
Starting from that, you could do analysis based on most chatty hosts.
Thanks, good base search.
*NOTE: We could search by errors but we'd like to narrow down the time window rather than eliminate errors. Given the number of servers involved, reducing the search space is seen at the logical first step.