How to get earliest and latest time for the last one hour to compare with the same hour last week for which I don't know the earliest and latest time?
For last one hour, earliest=-1h@h latest=@h
is working, but I don't know how to get the same hour last week for comparison purposes.
Kindly suggest
How about:
| tstats count AS hourlyCount WHERE earliest=-7d@d latest=now index=* by index, _time span=1h | eval now_hour=strftime(now(),"%H") | eval time_hour=strftime(_time,"%H") | where time_hour=now_hour-1
It looks at the previous hour and matches it for the same hour in the past 7 days
@mkarimi17 - perhaps you should try running it. It will give the same hour for each day, not just the two, and it will not compare last week's with this week's.
Or in simple way,
earliest=-1h@h-1w latest=@h-1w
Hello
What about?
earliest=-169h@h latest=-168h@h
Regards