I can find the number of clients talking to my deployment server by client group name like this.
index=_internal hostname=* component="Metrics" group="ds_connections_default" | stats dc(hostname) by name | addcoltotals labelfield=name label=TOTAL
this might not be the fastest or most efficient method and if you know a better way please let me know.
I want to run this search for the last month and compare to the month before that so that I get a number of clients per client group name with "coltotal" added last month report.
Does that make sense???
any help would be appreciated.
Remember that by default your _internal
index will only keep data for 30 days, so without storing summary data in another index you'd need to increase that to cover two months.
Try this
index=_internal hostname=* component="Metrics" group="ds_connections_default" earliest=-2mon@mon latest=@mon| chart dc(hostname) by name,date_month | addcoltotals labelfield=name label=TOTAL
that is why it needs to be in summary index where you store the result for each month rather running one 5 min query for the result from _internal logs. then you can mention month wise report.
Thanks Timewrap is almost the answer I was looking for a difference (i.e 39 new clients were added last month)
Like this - Number of clients last months subtract number of clients two months ago equals number of clients added
Mar Clients 120
Feb Clients -110
New Clients 20
20 clients added last month
Seems simple enough I just cant figure out how to do it in one search or report query?
Thanks everyone for your help
go for timewrap
this will do exactly what you need
Thanks I see the different Columns using the chart command.
then I can subtract one column from the other.
I am looking at the small app called "Timewrap" this might work for me
If I am not wrong with this search, you'll get 3 columns, name, month1, month2 which mean you can compare the data for last month with a month before that. Trick is to specify proper time period using earliest and latest. [to compare current month and last month, use earliest=-1mon@mon latest=now]
Thanks this is helping to get the previous two months of data. I still need to separate the two months and compare the results to see the change between months. the last month compered to this month type thing to get the difference. I guess it wasn't too clear. sorry...
Thanks again for the help 🙂
thanks much I'll try to lookup how to do that
summarize then run the comparison.