I have an event that should occour every day, I would like to visualise a a chart where I can see over the last month at what time of the day that event occurred (if it did occour)
Many thanks
If you are on Splunk Enterprise 7.0, you should check out Event Annotation.
https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartEventAnnotations
Hi
Daily event can we be extracted and give a field name as "daily_event"
Thereafter you can write below query:
index=<your_index> daily_event=* | stats count by daily_event, _time