Knowledge Management

Search optimization question

jonydupre
Path Finder

Hi all,

I had some trouble with a search but got it to work. But the search istelf isn't that "clean" I suppose.
Someone mentioned Timechart but I couldn't get it to work.

This is the search:

index=linux host="i*soe*" earliest=-1d@d latest=@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalA
| appendcols 
[search index=linux host="i*soe*" earliest=@d latest=now "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalB]
| appendcols 
[search index=linux earliest=-2d@d host="i*soe*" latest=-1d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalC]
| eval Gister=TotalA 
| eval Vandaag=TotalB
| eval Eergisteren=TotalC
| fields HealthchecksError, 2days ago, Yesterday, Today

Would there be a way to improve the search syntax wise?
Thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jonydupre,
your search isn't so clear, can you better describe what you want to have as result?
The total count of different hosts for each day?
eventually divided by HealthchecksError?

Anyway, reading you search I see that you don't need the first stats count (| stats count BY host ) because you have a dedup before and another stats count after.

Then I see that you used appendcols with the same search in a different period, while you could use timechart command, something like this:

 index=linux host="i*soe*" earliest=-2d@d latest=now "healthcheck: System not healthy" 
| timechart span=1d dc(host) AS n_hosts

If you want also differentiate the count of different hosts by HealthchecksError, you can add this clause to the timechart:

 index=linux host="i*soe*" earliest=-2d@d latest=now "healthcheck: System not healthy" 
| timechart span=1d dc(host) AS n_hosts BY HealthchecksError

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...