I am trying to write a search that will return a report of event times by hour for each sourcetype.
For example,
Source1 Source2 Source3 Total
1/1/17 1:00PM 5000 2000 500 7500
1/1/17 2:00PM 4000 1000 100 5100
Any assistance will be appreciated.
This is should get you started
| tstats count where index=* by sourcetype _time span=1h
| chart sum(count) limit=0 by _time span=1h sourcetype
| addtotals fieldname=Total
| where Total > 0
try like this:
index=_internal|eventstats count by sourcetype|timechart span=1h c by sourcetype | addtotals
Thanks! this one only gave me the database stats but its a good starting point.
This is should get you started
| tstats count where index=* by sourcetype _time span=1h
| chart sum(count) limit=0 by _time span=1h sourcetype
| addtotals fieldname=Total
| where Total > 0
Thanks, that seemed to do the trick!!