Hi ddrillic,
how about tstats
? Try this run everywhere command:
| tstats count where index=* by _time, index, sourcetype
Hope this helps ...
cheers, MuS
Hi ddrillic,
how about tstats
? Try this run everywhere command:
| tstats count where index=* by _time, index, sourcetype
Hope this helps ...
cheers, MuS
Thank you experts.
I would include the span parameter as well, since the requirement is to bucket by time
| tstats count where index=* by _time, index, sourcetype span=1d