Hi pkcbailey,
you can either use chart
or timechart
for this. use either of the following two examples:
your search here earliest=-1mon@mon latest=-0mon@mon date_hour>=00 AND date_hour<=15 | bucket _time span=1d | chart count over _time by host
or
your search here earliest=-1mon@mon latest=-0mon@mon date_hour>=00 AND date_hour<=15 | timechart span=1d count by host
both examples will return a daily event count by host over the last month.
Hope that helps ...
cheers, MuS
Hi pkcbailey,
you can either use chart
or timechart
for this. use either of the following two examples:
your search here earliest=-1mon@mon latest=-0mon@mon date_hour>=00 AND date_hour<=15 | bucket _time span=1d | chart count over _time by host
or
your search here earliest=-1mon@mon latest=-0mon@mon date_hour>=00 AND date_hour<=15 | timechart span=1d count by host
both examples will return a daily event count by host over the last month.
Hope that helps ...
cheers, MuS