Dashboards & Visualizations

How to show the count that are coming on one date

aditsss
Motivator

Hi Team,

I have created one query to show case the count with date my query is below:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount

Now the issue is that I am getting the counts on one single day like this:

2023-07-06                                                                       1

                                                                                                 29

                                                                                                 42

How can I create query for this.

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

do you want the average, the max or all the values in the same row?

if avg or max, you can use this function in the stats command:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount

if you want all the values in one row, add nomv at the end:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

do you want the average, the max or all the values in the same row?

if avg or max, you can use this function in the stats command:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount

if you want all the values in one row, add nomv at the end:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @aditsss ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...