Hello,
I am trying to add another index column to this table. Currently using the search below.
| tstats count where index IN (network) by _time span=1h
| rename count as Network_Logs
| eval _time=strftime(_time, "%m-%d %H:%M")
| tstats count where index IN (network, proxy) by _time span=1h
| rename count as Network_Logs
| eval _time=strftime(_time, "%m-%d %H:%M")
Adding another index such as proxy doesn't seem to work just adds to the total count. Is there anyway to count separate indexes by 1 hour intervals?
You have to split by index as well. Try this
| tstats count where index IN (network, proxy) by _time span=1h index
| timechart span=1h max(count) by indexThe tstats will give you an index column as well as count, then the timechart will convert that to a timechart. Note that you need to use max(count) here.
Note you can also do this simply with tstats using prestats and chart, i.e.
| tstats prestats=t count where index IN (network, proxy) by _time span=1h index
| chart count by _time indexThis way you just use chart count and you don't need the max.
That worked. Thank you for the help!
You have to split by index as well. Try this
| tstats count where index IN (network, proxy) by _time span=1h index
| timechart span=1h max(count) by indexThe tstats will give you an index column as well as count, then the timechart will convert that to a timechart. Note that you need to use max(count) here.
Note you can also do this simply with tstats using prestats and chart, i.e.
| tstats prestats=t count where index IN (network, proxy) by _time span=1h index
| chart count by _time indexThis way you just use chart count and you don't need the max.
You can also use the tstats with prestats with count.
| tstats prestats=t count where index IN (network,proxy) by index _time span=1h
| timechart span=1h count by index