Reporting

contingency table cell values

jrstear
Path Finder

"daysago=5 | ctable host date_wday" produces a table with hosts on rows, dates on columns, and total message count in the cells, but takes a while as it must go through all the logs and count them. I have summary index records with fields orig_host and daily_count, but how do I get it into the same format as above?

More generally: it'd be handy if ctable took an optional argument to indicate what values were put in the cells, eg "daysago=5 index=summary search_name=daily_count_by_host | ctable orig_host wday value=daily_count". It'd also be nice to be able to control the sort order of rows and columns, eg via a preceding sort. Maybe there is already a way to do this?

Thanks for any help!

-jon

Tags (2)

Stephen_Sorkin
Splunk Employee
Splunk Employee

First note that ctable is roughly equivalent to chart. The following two give the same results, except for the limit in series that will be shown:

... | ctable x y
... | chart count by x y

In your case, you don't want the count of summary events but rather the sum of the daily_count field. So your search will be:

daysago=5 index=summary search_name=daily_count_by_host
| chart sum(daily_count) by orig_host wday

jrstear
Path Finder

nevermind, timechart is good. thanks again.

0 Karma

jrstear
Path Finder

eggcellent - thanks! hmm, the cli behavior is unexpected - eg pipe to less shows incomplete results. i'm aiming for a cli that shows top N chatty hosts - any pointers on that? (i don't know if i should submit a separate question)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...