Hi,
I am trying to get the timechart span = 1h , for the APIs appearing in the events. search query is like this ?
index=home sourcetype=logs "Keyword" | timechart count span=1h as count | sort _time | reverse
there will be different keyword but the underline search will be different like keyword1, keyword2, keyword3 etc, I want to get the timechart by each keyword. how that can be done.
Are the kewords fixed values? If yes, try this
index=home sourcetype=logs "keyword1" OR "keyword2" OR "keyword3"....
| eval keyword=case(searchmatch("keyword1"),"Keyword1", searchmatch("keyword2"),"Keyword2",.....rest of the keywords)
| timechart count span=1h as count by keyword | reverse
Are the kewords fixed values? If yes, try this
index=home sourcetype=logs "keyword1" OR "keyword2" OR "keyword3"....
| eval keyword=case(searchmatch("keyword1"),"Keyword1", searchmatch("keyword2"),"Keyword2",.....rest of the keywords)
| timechart count span=1h as count by keyword | reverse
Thanks Somesh, it works. I want to accept this as answer but not getting that option.
Here you go.