Dashboards & Visualizations

How to show the count that are coming on one date

aditsss
Motivator

Hi Team,

I have created one query to show case the count with date my query is below:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount

Now the issue is that I am getting the counts on one single day like this:

2023-07-06                                                                       1

                                                                                                 29

                                                                                                 42

How can I create query for this.

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

do you want the average, the max or all the values in the same row?

if avg or max, you can use this function in the stats command:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount

if you want all the values in one row, add nomv at the end:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

do you want the average, the max or all the values in the same row?

if avg or max, you can use this function in the stats command:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d max(records) AS RecordCount

if you want all the values in one row, add nomv at the end:

index="abc*" sourcetype=600000304_gg_abs_ipc2 source!="/var/log/messages" "Total msg processed for trim reage file:"
| rex "Total msg processed for trim reage file:(?<records>\d+)"
| timechart span=1d values(records) AS RecordCount
| nomv RecordCount

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @aditsss ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...