I use the below query to find the index size, how can I modify the query to get the comparision between todays's index size with yesterday's?
| eventcount summarize=false index=* report_size=true | eval MB=(size_bytes/1024)/1024 | stats sum(MB) by index, server
When I tried to change the label with GB I am not getting the percentage value.
index=_internal source=license_usage.log type=Usage earliest=-2d@d latest=@d
| eval Day=if(_time
Hi,
When I tried to change the label with GB I am not getting the percentage value.
index=_internal source=license_usage.log type=Usage earliest=-2d@d latest=@d
| eval Day=if(_time
Hi Mayur,
In dashboard I think the yesterday's count is showing as day b4 yesterday's count and vice versa. How to change the lable? need to add GB to the label, and has to be rounded off to 2 digits
you can change the label @ | eval Day=if(_time<relative_time(now(),"-1d@d"),"Yesterday","Day_Before_Yesterday")
this level.
and add to get the results in GB
| stats sum(eval(round((b/1024)/1024/1024,2))) AS volume_b by idx Day
Thank you. Is it possible to find the difference between the two datas and showing the % change?
Yes absolutely,
here you go:
index=_internal source=*license_usage.log* type=Usage earliest=-2d@d latest=@d
| eval Day=if(_time<relative_time(now(),"-1d@d"),"Yesterday","Day_Before_Yesterday")
| stats sum(eval((b/1024)/1024)) AS volume_b by idx Day
| chart max(volume_b) over idx by Day | eval %change=((Yesterday-Day_Before_Yesterday)/Yesterday)*100
If this helps you, accept the answer to close this question
Hi
Could you pls try this ?
index=_internal source=*license_usage.log* type=Usage earliest=-1d@d latest=now
| eval Day=if(_time<relative_time(now(),"@d"),"Yesterday","Today")
| stats sum(eval((b/1024)/1024)) AS volume_b by idx Day
| chart max(volume_b) over idx by Day
let me know if this helps!
yes, it is working but it shows only 14 indexes, we have may.
May I know the query for yesterday and day before yesterday?
well, eventcount
considers the summary from the beginning and not counting on daily basis that is why my query focus on the specific period you are looking for so you won't see the indexes which ain't contributing to license usage within specified period.
here you go:
index=_internal source=*license_usage.log* type=Usage earliest=-2d@d latest=@d
| eval Day=if(_time<relative_time(now(),"-1d@d"),"Yesterday","Day_Before_Yesterday")
| stats sum(eval((b/1024)/1024)) AS volume_b by idx Day
| chart max(volume_b) over idx by Day