Hi Team,
I have created one query to show case the count with date my query is below:
index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
Now the issue is that I am getting the counts on one single day like this:
2023-07-06 1
29
42
How can I create query for this.
Hi @aditsss,
do you want the average, the max or all the values in the same row?
if avg or max, you can use this function in the stats command:
index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount
if you want all the values in one row, add nomv at the end:
index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount
Ciao.
Giuseppe
Hi @aditsss,
do you want the average, the max or all the values in the same row?
if avg or max, you can use this function in the stats command:
index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount
if you want all the values in one row, add nomv at the end:
index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount
Ciao.
Giuseppe
hi @aditsss ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉