I have found a lot of ways to do one or the other of these, but short summary of what we have with theoretical numbers
10 hosts
10 logs per host going to one index
I would like to use the index as a starting point since I am specifically looking for event count that goes to that index. (Java Logs)
How would I graph the following please?
over 7 day period, what is the event count per log per host - 30 min buckets - end result would be something like...
host1 - log1 - 8:00-8:30 50 events
host1 - log2 - 8:00-8:30 50 events
host1 - log3 - 8:00-8:30 50 events
host1 - log4 - 8:00-8:30 50 events
host1 - log5 - 8:00-8:30 50 events
host2 - log1 - 8:00-8:30 50 events
host2 - log2 - 8:00-8:30 50 events
host2 - log3 - 8:00-8:30 50 events
host2 - log4 - 8:00-8:30 50 events
host2 - log5 - 8:00-8:30 50 events
etc...
Thanks
John
Give this a try
| tstats count WHERE index=YourIndexHere by _time host sourcetype span=30m
Give this a try
| tstats count WHERE index=YourIndexHere by _time host sourcetype span=30m
Love it so far - thanks!
Spoke a little too soon... the table is exactly what I need.
The graph is just total count and is not separating by host / sourcetype. Is this something I need to configure on the graph or something that should be configured on the query? Worse case I can export to excel and graph on a pivot chart but would be nice to have it on a dashboard.
Thanks
JD
Try this
| tstats count WHERE index=YourIndexHere by _time host sourcetype span=30m | eval metric=host.":".sourcetype | timechart span=30m sum(count) by metric
Love it - thank you very much for your quit response - really appreciate it!