Knowledge Management

Create summary index to count events by sourcetype every hour

joesrepsolc
Communicator

Trying to create a scheduled report, to fire off a search and populate a summary index. Just want counts for each sourcetype into a new index called "index_summary". Planning to use this to track volume over time, changes in volume, possibly even do an alerrt if it changes by say 300% +/- etc.

Trying
|tstats count where index=* by date_hour index sourcetype

but not really seeing the results as they will need to be. Looking to populate Date/Time (most likelys hourly), index, sourcetype, count. Any help would be appreciated.

Labels (1)
0 Karma

to4kawa
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...