Hi all,
I am new to splunk and I am trying to form a timechart for my following question:
How many unique entityx
were created in last 7 days and what's the total number of unique entityx
?
To do this, here is what I am doing
index=* host=* `logRecordType(entityx) | timechart dc(entityx) AS "Number of Unique Unique"
But how do I add the total number of unique entityx in my chart......!!!!!
HI try this:
...... | timechart span=7d values(entityx) AS values dc(entityx) AS
"Number of Unique Unique"
If you need only for the last 7 days:
... | timechart span=7d values(entityx) AS values dc(entityx) AS
"Number of Unique Unique" |head 1
HI try this:
...... | timechart span=7d values(entityx) AS values dc(entityx) AS
"Number of Unique Unique"
If you need only for the last 7 days:
... | timechart span=7d values(entityx) AS values dc(entityx) AS
"Number of Unique Unique" |head 1
jaimini1414, I'm happy to see that you are satisfy.
I also see that you accepted. BUT MY KARMA HISTORY SHOWS A Down VOTE from you.Why?
Hey thanks for your respond...But I would like to have the total number of unique ones....i still dont see it.
I dont mind seeing the total in the legends as well...But still no I dont see that...
I don"t understand you very well, assuming that you have many "Number of Unique Unique" , do you want thier total ? if it is the case , remove head and do :
......|addtotals fieldname="Number of Unique Unique"
This worked...Thankss...!!!