So I have a search that queries hosts that are reporting their syslogs via the Meta Hoot! application for Splunk. As of now the search is only a Single Value, however, I would like to add a trend indicator using 'timechart' for the previous 24 hours.
Here is the search string.
inputlookup meta_woot where index=* sourcetype=syslog | stats dc(host) as "Hosts"
How can I incorporate 'timechart' to add the uptick/downtick, trend indicator?
Thanks for the quick reply.
I just tried using the following to receive "no results found".
inputlookup meta_woot where index=* sourcetype=syslog | timechart span=1d count by host
I must be missing something.
That didn't seem to work for me 😞
Still receiving "No results found".
Any other suggestions?
Thanks for the help/input, it's very much appreciated.