Knowledge Management

Search optimization question

jonydupre
Path Finder

Hi all,

I had some trouble with a search but got it to work. But the search istelf isn't that "clean" I suppose.
Someone mentioned Timechart but I couldn't get it to work.

This is the search:

index=linux host="i*soe*" earliest=-1d@d latest=@d "healthcheck: System not healthy" | dedup host | stats count by host
| stats count as TotalA
| appendcols 
[search index=linux host="i*soe*" earliest=@d latest=now "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalB]
| appendcols 
[search index=linux earliest=-2d@d host="i*soe*" latest=-1d@d "healthcheck: System not healthy" | dedup host | stats count by host 
| stats count as TotalC]
| eval Gister=TotalA 
| eval Vandaag=TotalB
| eval Eergisteren=TotalC
| fields HealthchecksError, 2days ago, Yesterday, Today

Would there be a way to improve the search syntax wise?
Thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jonydupre,
your search isn't so clear, can you better describe what you want to have as result?
The total count of different hosts for each day?
eventually divided by HealthchecksError?

Anyway, reading you search I see that you don't need the first stats count (| stats count BY host ) because you have a dedup before and another stats count after.

Then I see that you used appendcols with the same search in a different period, while you could use timechart command, something like this:

 index=linux host="i*soe*" earliest=-2d@d latest=now "healthcheck: System not healthy" 
| timechart span=1d dc(host) AS n_hosts

If you want also differentiate the count of different hosts by HealthchecksError, you can add this clause to the timechart:

 index=linux host="i*soe*" earliest=-2d@d latest=now "healthcheck: System not healthy" 
| timechart span=1d dc(host) AS n_hosts BY HealthchecksError

Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...