This is a followup question to This.
http://answers.splunk.com/answers/301144/sum-of-new-events-over-time.html
Now further, say I have all these new events, the answer gave me the total for all new events together, which was perfect for that given case.
Now for further analysis, I'd like it to be a line of the total New events, for each Engine.
So with the answer I got this:
And I would like a different graph of total New events for each Engine, like:
So to split the results by Engine I got this:
host="MyHost" Status="New" | timechart count by Engine
That gives me a division by Engine, but once again, it shows me single values per day, and not the accumulated total.
I've tried:
host="MyHost" Status="New" | timechart count by Engine | accum count
- just adds another value named 'count' with 0
I'm obviously missing something basic in my understanding.
Thanks again in advance!
Try something like this
host="MyHost" Status="New" | timechart count by Engine | streamstats sum(*) as *
Try something like this
host="MyHost" Status="New" | timechart count by Engine | streamstats sum(*) as *
Perfect!
Thank you!