how to count the number of file transferred within one month by an user id using particular file and display events in below manner:
username filename count_of_files_tras_in1day count_of_files_trasferred_in_1week count_of_files_trasferred_in_1mon
What data do you have in your events?
I have file transfers events , I have got the first part of code but filtering it and displaying it based upon the count of file transfers in one day, one week and one month is where i am facing issue.
|bucket span=1mon _time
| eval day=strftime(_time,"%Y-%m-%d")
| eval week=strftime(_time, "%V")
| eval w_month=strftime(_time, "%d/%m")
|stats count(BASE_filename) as oneday by day | stats count(BASE_filename) as oneweek by week|stats count(BASE_filename) as onemonth by w_month