<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366495#M9566</link>
    <description>&lt;P&gt;If I have a set of keywords for which I need to obtained the above results. Is there a way in splunk I can automate to read the csv files for each keyword one at a time and generate the output in the format shown above.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2017 20:18:40 GMT</pubDate>
    <dc:creator>saifullakhalid</dc:creator>
    <dc:date>2017-11-13T20:18:40Z</dc:date>
    <item>
      <title>How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366485#M9556</link>
      <description>&lt;P&gt;I would like to search for keywords( mentioned below ) from the logs and create a report in the format shown&lt;/P&gt;

&lt;P&gt;Every keyword has different pattern and it lies in middle of requests which start with ?pyActivity=&lt;/P&gt;

&lt;P&gt;?ptActivity=...............................................PreActivity=DCBClaimSearch&amp;amp;HeaderButtonSectionName.................HTTP/1.1" 200 4502&lt;BR /&gt;
?&lt;BR /&gt;
ptActivity=...........................LanguageCode=&amp;amp;CountryCode=&amp;amp;PRODUCT_XXXX=XXXX=&amp;amp;LOB=&amp;amp;XXXXXCD=&amp;amp;Count=..........HTTP/1.1" 200 3402&lt;/P&gt;

&lt;P&gt;?ptActivity=xxxxxxxxxxxxxxxxxxxxxxxxxxxxx%20ℜquest_Type=&amp;amp;xxxxxxxxxxxxxx_xxxxxxxxxxxxxxx&amp;amp;ELEMENT_CD=⟪uageCode=&amp;amp;CountryCode=&amp;amp;PRODUCT_LINE_CDXXXX=&amp;amp;LOB=&amp;amp;LOB_XXX_CD=&amp;amp;Count= HTTP/1.1" 200 5092&lt;/P&gt;

&lt;P&gt;log format :&lt;/P&gt;

&lt;P&gt;1x.xx.xxx.xxx - - 11xxxxx4 [03/Oct/2017:08:01:54 -0400] - /pxxx/Gxxxxt/uxxxxxxxxx4[&lt;EM&gt;/!TABTHREAD1 HTTP/1.1 oxxx-xxx.xxx.net TIME:0/123717 "POST /pxxxb/Gxxxxt/uxxxxxxxxxxxxxxxxx4%5B&lt;/EM&gt;/!TABTHREAD1?ptActivity=Cxxxxxxxxx-xxxx.xxxxxx%20&amp;amp;Request_Type=&amp;amp;xxxxxTYPE_CD=COUNTRY&amp;amp;Exxxxxxxx_CD=&amp;amp;LanguageCode=&amp;amp;CountryCode=&amp;amp;PRODUCT_LINE_CD=&amp;amp;REGION_CD=&amp;amp;LOB=&amp;amp;LOB_SUB_CD=&amp;amp;Count= HTTP/1.1" 200 4011&lt;/P&gt;

&lt;P&gt;1x.xx.xxx.xxx  - - - [03/Oct/2017:08:01:54 -0400] - /pddddb/Gdddd/xxxxxxxxxxxxxxxxxx[&lt;EM&gt;/themeimages/h1expand_theme_ccddd.gif!!.gif HTTP/1.1 oxxxxxxxxxxx.aig.net TIME:0/12758 "GET / /pddddb/Gdddd/xxxxxxxxxxxxxxxxxx[&lt;/EM&gt;/themeimages/h1expand_theme_ccddd.gif!!.gif HTTP/1.1" 200 69&lt;/P&gt;

&lt;P&gt;1x.xx.xxx.xxx- - 1ssssss4 [03/Oct/2017:08:02:09 -0400] - /pxxxx/Gxxxxxt/uxxxxxxxxxxxxxxxxx4[&lt;EM&gt;/!TABTHREAD1 HTTP/1.1 oxxx-xxx.xx.net TIME:0/117091 "POST /pxxxb/Gxxxt/xxxxxxxxxxxxxxxxxxxxB&lt;/EM&gt;/!TABTHREAD1?ptActivity=ReloadSection&amp;amp;pzIxxxd=xxxxxxxxxxxxxxxxxxx&amp;amp;pzFromFrame=pyxxxx&amp;amp;pzxxxxxxxxxxxe=pyxxxxxxxxe&amp;amp;pzxxxxxxx=false&amp;amp;StreamName=AddPropertyDetails&amp;amp;BaseReference=xxxxxxxxxx.xxxxxxxxxxe.Prxxxxxxx&amp;amp;Stxxxxxxxxxxxss=xxxxxxx-Section&amp;amp;bClientValidation=true&amp;amp;FieldError=ERRORTEXT&amp;amp;PreActivity=&amp;amp;xxxxxxxxxge=true&amp;amp;HexxxxxxxxnName=SubxxxxxxorkObjectHeaderB&amp;amp;inStandardsMode=true&amp;amp;AJAXTrackID=5&amp;amp;pzHarnessID=HIDxxxxxxxxx HTTP/1.1" 200 4512&lt;/P&gt;

&lt;P&gt;reports to be generated:&lt;/P&gt;

&lt;P&gt;Report 1 :&lt;/P&gt;

&lt;P&gt;User                    Time            Protocol       server               Elapsed Time (Seconds)    Call     Status   Size       logName&lt;BR /&gt;
1ssssss4    17/Oct/04 01:15:00  HTTP/1.1    oxxxxxxxxxxx.net    0.201185    ptActivity=ReloadSection&amp;amp;pzIxxxd=xxxxxxxxxxxxxxxxxxx&amp;amp;pzFromFrame=pyxxxx&amp;amp;pzxxxxxxxxxxxe=pyxxxxxxxxe&amp;amp;pzxxxxxxx=false&amp;amp;StreamName=AddPropertyDetails&amp;amp;BaseReference=xxxxxxxxxx.xxxxxxxxxxe.Prxxxxxxx&amp;amp;Stxxxxxxxxxxxss=xxxxxxx-Section&amp;amp;bClientValidation=true&amp;amp;FieldError=ERRORTEXT&amp;amp;PreActivity=&amp;amp;xxxxxxxxxge=true&amp;amp;HexxxxxxxxnName=SubxxxxxxorkObjectHeaderB&amp;amp;inStandardsMode=true&amp;amp;AJAXTrackID=5&amp;amp;pzHarnessID=HIDxxxxxxxxxx    HTTP/1.1    200 6188    \508\access_log_10_04_2017&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366485#M9556</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2020-09-29T16:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366486#M9557</link>
      <description>&lt;P&gt;have you done any of these field extractions yet?  If not, can you share the log format?  We might be able to guess from the examples, but i see some instances where the user is a "-".  But then there are also other dashes that probably represent something?&lt;/P&gt;

&lt;P&gt;Also, is the timestamp in splunk for these events (_time) the same as the timestamp in the event?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 22:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366486#M9557</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-10T22:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366487#M9558</link>
      <description>&lt;P&gt;The log format is typically same as shown above &lt;BR /&gt;
- - 11xxxxx4   is same for all the lines &lt;BR /&gt;
- - -                only for static values like css, js, img, the user column is (-). &lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 22:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366487#M9558</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-10T22:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366488#M9559</link>
      <description>&lt;P&gt;timestamp in splunk you mean to say the format?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 23:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366488#M9559</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-10T23:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366489#M9560</link>
      <description>&lt;P&gt;I meant timestamp.  I was just wondering if these events in splunk already have the correct timestamp or fi that needs to be extracted as well.&lt;/P&gt;

&lt;P&gt;I won't have time tonight, but I can try put together the regex to pull the fields out of this data so you can create the report.  I think that's really all you need, right?  &lt;/P&gt;

&lt;P&gt;And if this is a common format like apache or something, then there is already probably an add-on that knows how to parse the events.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 23:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366489#M9560</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-10T23:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366490#M9561</link>
      <description>&lt;P&gt;yes ur correct we need to convert timestamp  to format (start_time,"%d/%m/%Y %I:%M:%S:%p") . &lt;/P&gt;

&lt;P&gt;&lt;I&gt;&lt;BR /&gt;
Yes ur right&lt;BR /&gt;
&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 23:36:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366490#M9561</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-10T23:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366491#M9562</link>
      <description>&lt;P&gt;yes ur correct we need to convert timestamp to format (start_time,"%d/%m/%Y %I:%M:%S:%p") . &lt;/P&gt;

&lt;P&gt;&lt;I&gt;&lt;BR /&gt;
Yes ur right&lt;BR /&gt;
&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 23:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366491#M9562</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-10T23:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366492#M9563</link>
      <description>&lt;P&gt;when i ask about the log format, this is what i have in mind.  Not an example of the log, but exactly what parameters are being used to create the log&lt;/P&gt;

&lt;P&gt;&lt;A href="http://httpd.apache.org/docs/current/mod/mod_log_config.html"&gt;http://httpd.apache.org/docs/current/mod/mod_log_config.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, not sure how you are calculating elapsed time with those examples.  Does it come from this part:  "TIME:0/117091" ??&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 14:40:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366492#M9563</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-11T14:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366493#M9564</link>
      <description>&lt;P&gt;This seems to work for me on those two events.  Except for the elapsed bit, still not sure how that is being calculated.  Also, in your second example event, the first dash (-) is right up against the IP.  I'm assuming there is actually a space there like the first event.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... |  rex "^(?&amp;lt;ip&amp;gt;\S+)(?:\s+\S+){2}\s+(?&amp;lt;user&amp;gt;\S+)\s+\[(?&amp;lt;time&amp;gt;[^\]]+)\](?:\s+\S+){2}\s+(?&amp;lt;protocol&amp;gt;\S+)\s+(?&amp;lt;server&amp;gt;\S+)\s+(?&amp;lt;elapsed&amp;gt;\S+)\s+\"(?&amp;lt;request&amp;gt;[^\"]+)\"\s+(?&amp;lt;status&amp;gt;\d+)\s+(?&amp;lt;bytes&amp;gt;\S+)" 
|  rex field=request "ptActivity=(?&amp;lt;call&amp;gt;.+)$"
|  table user,time,protocol,server,call,status,bytes,source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If this is what you want, you could also put these field extractions in props.conf for whatever sourcetype you all this on your search.  That way the fields will automatically be extracted for you.  So, you wouldn't need to use the rex commands to create them.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 14:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366493#M9564</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-11T14:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366494#M9565</link>
      <description>&lt;P&gt;It worked fine thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366494#M9565</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-13T20:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366495#M9566</link>
      <description>&lt;P&gt;If I have a set of keywords for which I need to obtained the above results. Is there a way in splunk I can automate to read the csv files for each keyword one at a time and generate the output in the format shown above.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366495#M9566</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2017-11-13T20:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366496#M9567</link>
      <description>&lt;P&gt;Thanks for your previous answer , I also need a reports like below,&lt;/P&gt;

&lt;P&gt;Report2: summary report&lt;/P&gt;

&lt;P&gt;Start Time  End Time      keyword  Total # of executions    Avg # of Executions per Hour      Min Resp Time Max Resp Time      Avg Resp Time    90th percentile Resp Time   Std Dev Of Resp Time    Min Size of Response    Max Size of Response    Avg Size of Response    90th percentile Size of Response    Std Dev of  Size of Response&lt;/P&gt;

&lt;P&gt;sample:&lt;BR /&gt;
Keyword1    17/Oct/04 00:11:46  17/Oct/04 23:24:05  2398    104  0.02   27.35   0.108   0.109   0.594   82  10342   4302.94 4543    424.21&lt;BR /&gt;
Keyword2    17/Oct/04 00:11:46  17/Oct/04 23:24:05  2398    103  0.03   22.35   0.119   0.107   0.583   89  10332   43394   4523    4324.21&lt;/P&gt;

&lt;P&gt;Report3: 24 hours &lt;/P&gt;

&lt;P&gt;Start Time  End Time      keyword  Total # of executions    Avg # of Executions per Hour      Min Resp Time Max Resp Time      Avg Resp Time    90th percentile Resp Time   Std Dev Of Resp Time    Min Size of Response    Max Size of Response    Avg Size of Response    90th percentile Size of Response    Std Dev of  Size of Response&lt;/P&gt;

&lt;P&gt;sample:&lt;/P&gt;

&lt;P&gt;keyword_1   17/Oct/04 00:00:00  17/Oct/04 00:59:59  4   4   0.056125    0.070999    0.0613225   0.070999    0.00671778  3617    4533    3886.75 4533    437.5083809&lt;BR /&gt;
keyword_1   17/Oct/04 01:00:00  17/Oct/04 01:59:59  3   3   0.058215    0.080105    0.066264    0.080105    0.012039662 3780    4548    4036    4548    443.4050067&lt;BR /&gt;
keyword_1   17/Oct/04 02:00:00  17/Oct/04 02:59:59  9   9   0.039571    0.083275    0.058887778 0.083275    0.015465193 3628    4549    4018.777778 4549    400.1539634&lt;BR /&gt;
keyword_1   17/Oct/04 03:00:00  17/Oct/04 03:59:59  8   8   0.038187    0.062873    0.053408625 0.062873    0.009202517 3615    4545    3834    4545    296.6532367&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
keyword_1   17/Oct/04 &lt;STRONG&gt;23:00:00&lt;/STRONG&gt;  17/Oct/04 &lt;STRONG&gt;23:59:59    5&lt;/STRONG&gt; 5   0.040078    0.07862 0.0598834   0.07862 0.013636071 3616    3628    3618.6  3628    5.272570531&lt;/P&gt;

&lt;P&gt;similarly for keyword_2, _3 and soon.&lt;/P&gt;

&lt;P&gt;Note My log format is same as shown in question initially.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366496#M9567</guid>
      <dc:creator>saifullakhalid</dc:creator>
      <dc:date>2020-09-29T16:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366497#M9568</link>
      <description>&lt;P&gt;If the csv file is a lookup in splunk, then that could be doable using a subsearch I believe, but you'd probably want to create field extractions in props for that field, as opposed to using rex in the command.  &lt;/P&gt;

&lt;P&gt;Or if it's a pretty static list, you can just filter for those keywords in the base search too.  Or you could create a dashboard with a dropdown of keywords and have the search update as you select a different keyword.  &lt;/P&gt;

&lt;P&gt;So you have a few different options, but as far as just "looping through a csv", that's not really how splunk works, no.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366497#M9568</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-14T21:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create the report for the log access (Between 00:00:00 and 23:59:59) in a format shown</title>
      <link>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366498#M9569</link>
      <description>&lt;P&gt;Are you familiar with the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Stats"&gt;stats command&lt;/A&gt;?  If not, you might want to play around with it.  I'm not going to type all of these out but hopefully this will give you the right idea&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "^(?\S+)(?:\s+\S+){2}\s+(?\S+)\s+\[(?[^\]]+)\](?:\s+\S+){2}\s+(?\S+)\s+(?\S+)\s+(?\S+)\s+\"(?[^\"]+)\"\s+(?\d+)\s+(?\S+)" 
    | rex field=request "ptActivity=(?&amp;lt;call&amp;gt;.+)$"
    | bucket _time span=1h
    | stats count min(elapsed) as min_resp, max(elapsed) as max_resp, min(bytes) as min_size, max(bytes) as max_size by call _time
    | stats sum(count) as total_events, avg(count) as avg_per_hour, min(min_resp) as min_resp, max(max_resp) as max_resp, min(min_size) as min_size, max(max_size) as max_size by call
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The bucket command will essentially floor all of the timestamps to the hour.  Next we get all of our stats by the keyword and hour, because we need to calculate avg events per hour.  Now that we have those counts by the hour/keyword, we can get the average per hour and then all of the remaining numbers grouped to just the keyword with another stats command.&lt;/P&gt;

&lt;P&gt;Hopefully that helps. Note, you could pretty much eliminate that last step for your last report, since it looks like you do want the data by hour.  And in that case, I'm guessing total events and avg per hour would be the same number, if you're aggregating over the hour.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 22:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-do-you-create-the-report-for-the-log-access-Between-00-00-00/m-p/366498#M9569</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-14T22:09:05Z</dc:date>
    </item>
  </channel>
</rss>

