Hi All,
Input logs are forwarded from a syslog server. We extracted server name and user id from the logs. Our requirement is to find the count of users logged in a particular server per hour. So we used the below query but the result is varying at every execution. Could you please help with this issue?
| table _time, server, userdetails
| timechart span=1h dc(userdetails) by server
Thanks in advance.
At every execution you timerange is getting differed, so obviously if you stick to your earliest and latest of time, then your result will be constant. You can add the below in your query and see to yourself
index=abc earliest=-2h@h latest=-1h@h
| table _time, server, userdetails
| timechart span=1h dc(userdetails) by server
Maybe your time picker will be Last ...
.
So at each searching, search range and the count of results are different.