Hello Splunkers.
i made a splunk search to count the number of blocked URLs as a single value in a one day span of 3days period of search.
here's my search:
index=proxy action=blocked
| bin _time span=1d
| stats count(http_url) by _time
and here's the results:
i want to show it in thousands of tried, i tried this this search but the results doesnt appear:
index=proxy action=blocked
| bin _time span=1d
| eval url_count= http_url/1000
| stats count(url_count) by _time
but there are no results
please help me with it, thanks ^_^
try this.
index=proxy action=blocked
| bin _time span=1d
| stats count(http_url) as http_url_count by _time
| eval http_url_count=http_url_count/1000