Hello,
I am getting successful logins from each server which is like 4000 per day from Each server. But some days that number is going high.
How can I compare successful logins with yesterday and how to get the difference between yesterday and today?
and create a notable event which is more than normal logins by comparing 2.
Any help would be appreciated!
Thanks,
Try this logic :
index=_internal earliest=-1d@d latest=now
| timechart count span=1d
| timewrap d
| rename 1day_before as Yesterday latest_day as Today
| eval diff=Yesterday-Today
Try this logic :
index=_internal earliest=-1d@d latest=now
| timechart count span=1d
| timewrap d
| rename 1day_before as Yesterday latest_day as Today
| eval diff=Yesterday-Today