<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write a conditional timechart search that will not count more than 1 event per day? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169738#M48512</link>
    <description>&lt;P&gt;Thanks woodcock, this is useful and where a report is empty it indicates there were no days with 0 logs. Is there a way to inversely have a record for each day at least 1 log was present? For instance, a "Yes" for each day during the time period at least 1 log event matches the search string. &lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2015 22:03:52 GMT</pubDate>
    <dc:creator>splunkrsherman</dc:creator>
    <dc:date>2015-06-24T22:03:52Z</dc:date>
    <item>
      <title>How to write a conditional timechart search that will not count more than 1 event per day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169736#M48510</link>
      <description>&lt;P&gt;I'd like an efficient search that will return either "Yes" or "No" for a timechart per day. I would imagine a limiting function and some evaluation may be necessary. I'm trying to avoid having splunk chew through counting more than 1 log record per day to simply confirm logs were simply present for that condition in the day. &lt;/P&gt;

&lt;P&gt;I would imagine the search would like: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;base search | timechart span=1d limit 1 as count | eval if(count &amp;gt; 0), "Yes", "No"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 23 Jun 2015 00:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169736#M48510</guid>
      <dc:creator>splunkrsherman</dc:creator>
      <dc:date>2015-06-23T00:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a conditional timechart search that will not count more than 1 event per day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169737#M48511</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Index=* | dedup date_month date_mday host sourcetype | timechart span=1d | where count=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will show you sources of data that have not reported events in any full day, the most efficient way.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2015 01:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169737#M48511</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-23T01:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a conditional timechart search that will not count more than 1 event per day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169738#M48512</link>
      <description>&lt;P&gt;Thanks woodcock, this is useful and where a report is empty it indicates there were no days with 0 logs. Is there a way to inversely have a record for each day at least 1 log was present? For instance, a "Yes" for each day during the time period at least 1 log event matches the search string. &lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 22:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169738#M48512</guid>
      <dc:creator>splunkrsherman</dc:creator>
      <dc:date>2015-06-24T22:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a conditional timechart search that will not count more than 1 event per day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169739#M48513</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* | dedup date_month date_mday host sourcetype | timechart span=1d | eval OK=if(count=0,"NO","YES")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Don't forget to "Accept" the answer.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 13:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169739#M48513</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-26T13:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a conditional timechart search that will not count more than 1 event per day?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169740#M48514</link>
      <description>&lt;P&gt;woodcock, thanks for your continued response. &lt;/P&gt;

&lt;P&gt;Seems like the right track, but timechart will not work for me without supplying a field to chart by, I'm guessing I should use count. When I do that it dedups and rolls all into the most recent date/time with a count of days (7 for a week). &lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 17:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-conditional-timechart-search-that-will-not-count/m-p/169740#M48514</guid>
      <dc:creator>splunkrsherman</dc:creator>
      <dc:date>2015-06-26T17:24:54Z</dc:date>
    </item>
  </channel>
</rss>

