Try this
your search |chart count over Exceptions by <day field>
or if you don't have a day field
your search |chart span=1d count over Exceptions by _time
Try this
your search |chart count over Exceptions by <day field>
or if you don't have a day field
your search |chart span=1d count over Exceptions by _time
It shows results only for first exception.!!
Do you have other Exceptions in the events? Just try this to see how it works
index=* earliest=-7d|chart count over sourcetype by _time span=1d
great working fine. But now the problem is dates are in epoch format. How to convert that in to normal format?
Found Now it is working fine.
index=_internal sourcetype=* earliest=-7d | eval time=strftime(_time,"%m/%d/%y") |chart count over sourcetype by time span=1d
Thank you renjith
You are welcome, Please mark as answer so that the thread will be closed
Just convert time before chart ie
index=* earliest=-7d|eval _time=strftime(_time,"%d-%m-%Y")|chart count over sourcetype by _time span=1d
You can use other variables instead of _time as well.
If you got the answer, just mark as answer so that the thread will be closed