Hello
I have this search:
earliest=-7d@d latest=@d source="/var/log/snmptrapfmt.log" (timeout_url="*.GE" OR timeout_url="*.tv" OR unavailable) AND NOT (timeout_url="*.com") | timechart count by timeout_url
and the result of this search is here: http://imageshack.us/photo/my-images/10/mollq.jpg/
Does somebody know how to remove/exclude from search events that do not occur in each day e.g. l(pink), w(dark green)
Perhaps this will help you...
your_search | eventstats dc(date_wday) AS daysaweek by url | where daysaweek > 6
Perhaps...
/kristian
Perhaps this will help you...
your_search | eventstats dc(date_wday) AS daysaweek by url | where daysaweek > 6
Perhaps...
/kristian
Thanks @kristian.kolb, it's working 😉