<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to generate or repeat the search condition that generates some stats for multiple days? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584203#M203432</link>
    <description>&lt;P&gt;This is because the times are being bucketed into days - try it this way&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search ...
| bin _time as time span=1d
| rex "elapsedTime=(?&amp;lt;ElapsedTime&amp;gt;.*?),\s*MLTime"
| rex "X\-ml\-timestamp\: (?&amp;lt;TimeStamp&amp;gt;.*?)\s*\n*X-ml-maxrows"
| rex "X\-ml\-size\: (?&amp;lt;size&amp;gt;.*?)\s*\n*X-ml-page"
| rex "X\-ml\-page\: (?&amp;lt;page&amp;gt;.*?)\s*\n*X-ml-count"
| rex "X\-ml\-elapsed\-time\: (?&amp;lt;MLelapsed&amp;gt;.*?)\s*\n*X-ml-timestamp"
| stats max(size) AS Page_Size max(_time) AS End_Time min(_time) AS Start_Time max(page) as Pages count(page) AS Total_Pages max(ElapsedTime) AS Max_ElapsedTime min(ElapsedTime) AS Min_ElapsedTime avg(ElapsedTime) AS Avg_ElapsedTime max(MLelapsed) AS Max_MLElapsedTime min(MLelapsed) AS Min_MLElapsedTime avg(MLelapsed) AS Avg_MLElapsedTime by time
| eval CASS_Date=strftime(Start_Time, "%Y-%m-%d")
| eval CASS_Duration= (End_Time-Start_Time)/60
| eval End_Time=strftime(End_Time, "%Y/%m/%d %T.%3Q")
| eval Start_Time=strftime(Start_Time, "%Y/%m/%d %T.%3Q")
| table CASS_Date Start_Time End_Time CASS_Duration Page_Size Pages Total_Pages Max_ElapsedTime Min_ElapsedTime Avg_ElapsedTime Max_MLElapsedTime Min_MLElapsedTime Avg_MLElapsedTime&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 09 Feb 2022 07:21:42 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-02-09T07:21:42Z</dc:date>
    <item>
      <title>How to generate or repeat the search condition that generates some stats for multiple days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584052#M203393</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;using logs i am generating some stats that are needed to track the performance of my app on daily basis using the below query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;search ...| rex "elapsedTime=(?&amp;lt;&lt;STRONG&gt;ElapsedTime&lt;/STRONG&gt;&amp;gt;.*?),\s*MLTime" | rex "X\-ml\-timestamp\: (?&amp;lt;&lt;STRONG&gt;TimeStamp&lt;/STRONG&gt;&amp;gt;.*?)\s*\n*X-ml-maxrows" | rex "X\-ml\-size\: (?&amp;lt;&lt;STRONG&gt;size&lt;/STRONG&gt;&amp;gt;.*?)\s*\n*X-ml-page" | rex "X\-ml\-page\: (?&amp;lt;&lt;STRONG&gt;page&lt;/STRONG&gt;&amp;gt;.*?)\s*\n*X-ml-count"&amp;nbsp; | rex "X\-ml\-elapsed\-time\: (?&amp;lt;&lt;STRONG&gt;MLelapsed&lt;/STRONG&gt;&amp;gt;.*?)\s*\n*X-ml-timestamp" | stats max(size) AS Page_Size max(_time) AS End_Time min(_time) AS Start_Time max(page) as Pages count(page) AS Total_Pages max(ElapsedTime) AS Max_ElapsedTime min(ElapsedTime) AS Min_ElapsedTime avg(ElapsedTime) AS Avg_ElapsedTime max(MLelapsed) AS Max_MLElapsedTime min(MLelapsed) AS Min_MLElapsedTime avg(MLelapsed) AS Avg_MLElapsedTime | eval CASS_Date=strftime(Start_Time, "%Y-%m-%d") | eval CASS_Duration= (End_Time-Start_Time)/60 | eval End_Time=strftime(End_Time, "%Y/%m/%d %T.%3Q") | eval Start_Time=strftime(Start_Time, "%Y/%m/%d %T.%3Q") | table CASS_Date Start_Time End_Time CASS_Duration Page_Size Pages Total_Pages Max_ElapsedTime Min_ElapsedTime Avg_ElapsedTime Max_MLElapsedTime Min_MLElapsedTime Avg_MLElapsedTime&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sivakesava574_0-1644305647379.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17846iDA0E25F36F79E314/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sivakesava574_0-1644305647379.png" alt="Sivakesava574_0-1644305647379.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;can someone please help me to perform the same above for multiple days with single query instead of i manually collecting these stats on daily basis&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 07:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584052#M203393</guid>
      <dc:creator>Sivakesava574</dc:creator>
      <dc:date>2022-02-08T07:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate or repeat the search condition that generates some stats for multiple days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584057#M203397</link>
      <description>&lt;P&gt;This could work:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;search ... &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;earliest=-7d@d&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2" color="#FF0000"&gt;&lt;STRONG&gt;| bucket _time span=1d&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| rex "elapsedTime=(?&amp;lt;ElapsedTime&amp;gt;.*?),\s*MLTime"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| rex "X\-ml\-timestamp\: (?&amp;lt;TimeStamp&amp;gt;.*?)\s*\n*X-ml-maxrows"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| rex "X\-ml\-size\: (?&amp;lt;size&amp;gt;.*?)\s*\n*X-ml-page"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| rex "X\-ml\-page\: (?&amp;lt;page&amp;gt;.*?)\s*\n*X-ml-count"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| rex "X\-ml\-elapsed\-time\: (?&amp;lt;MLelapsed&amp;gt;.*?)\s*\n*X-ml-timestamp"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| stats max(size) AS Page_Size max(_time) AS End_Time min(_time) AS Start_Time max(page) as Pages count(page) AS Total_Pages max(ElapsedTime) AS Max_ElapsedTime min(ElapsedTime) AS Min_ElapsedTime avg(ElapsedTime) AS Avg_ElapsedTime max(MLelapsed) AS Max_MLElapsedTime min(MLelapsed) AS Min_MLElapsedTime avg(MLelapsed) AS Avg_MLElapsedTime &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;BY _time&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| eval CASS_Date=strftime(Start_Time, "%Y-%m-%d")&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| eval CASS_Duration= (End_Time-Start_Time)/60&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| eval End_Time=strftime(End_Time, "%Y/%m/%d %T.%3Q")&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| eval Start_Time=strftime(Start_Time, "%Y/%m/%d %T.%3Q")&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;| table &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;_time&lt;/FONT&gt;&lt;/STRONG&gt; CASS_Date Start_Time End_Time CASS_Duration Page_Size Pages Total_Pages Max_ElapsedTime Min_ElapsedTime Avg_ElapsedTime Max_MLElapsedTime Min_MLElapsedTime Avg_MLElapsedTime&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 08:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584057#M203397</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-02-08T08:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate or repeat the search condition that generates some stats for multiple days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584076#M203405</link>
      <description>&lt;P&gt;it worked but, i see some of the fields are not giving the values.&lt;/P&gt;&lt;P&gt;Start_Time,End_Time,CASS_Duration&lt;/P&gt;&lt;P&gt;2022/02/02 00:00:00.000, 2022/02/02 00:00:00.000, 0&lt;/P&gt;&lt;P&gt;these values are populating when running for single day&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 10:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584076#M203405</guid>
      <dc:creator>Sivakesava574</dc:creator>
      <dc:date>2022-02-08T10:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate or repeat the search condition that generates some stats for multiple days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584203#M203432</link>
      <description>&lt;P&gt;This is because the times are being bucketed into days - try it this way&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search ...
| bin _time as time span=1d
| rex "elapsedTime=(?&amp;lt;ElapsedTime&amp;gt;.*?),\s*MLTime"
| rex "X\-ml\-timestamp\: (?&amp;lt;TimeStamp&amp;gt;.*?)\s*\n*X-ml-maxrows"
| rex "X\-ml\-size\: (?&amp;lt;size&amp;gt;.*?)\s*\n*X-ml-page"
| rex "X\-ml\-page\: (?&amp;lt;page&amp;gt;.*?)\s*\n*X-ml-count"
| rex "X\-ml\-elapsed\-time\: (?&amp;lt;MLelapsed&amp;gt;.*?)\s*\n*X-ml-timestamp"
| stats max(size) AS Page_Size max(_time) AS End_Time min(_time) AS Start_Time max(page) as Pages count(page) AS Total_Pages max(ElapsedTime) AS Max_ElapsedTime min(ElapsedTime) AS Min_ElapsedTime avg(ElapsedTime) AS Avg_ElapsedTime max(MLelapsed) AS Max_MLElapsedTime min(MLelapsed) AS Min_MLElapsedTime avg(MLelapsed) AS Avg_MLElapsedTime by time
| eval CASS_Date=strftime(Start_Time, "%Y-%m-%d")
| eval CASS_Duration= (End_Time-Start_Time)/60
| eval End_Time=strftime(End_Time, "%Y/%m/%d %T.%3Q")
| eval Start_Time=strftime(Start_Time, "%Y/%m/%d %T.%3Q")
| table CASS_Date Start_Time End_Time CASS_Duration Page_Size Pages Total_Pages Max_ElapsedTime Min_ElapsedTime Avg_ElapsedTime Max_MLElapsedTime Min_MLElapsedTime Avg_MLElapsedTime&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 09 Feb 2022 07:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-or-repeat-the-search-condition-that-generates/m-p/584203#M203432</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-09T07:21:42Z</dc:date>
    </item>
  </channel>
</rss>

