Hi,
Is it possible to run the same search with diffrent search time?
My requirement to have the count of transaction for particular hour in last 5 weeks , report looks as below:
Tran Type 25/Apr/13 07.00 -08.00 24/Apr/13 07.00 -08.00 23/Apr/13 07.00 -08.00
Get 100 80 95
Post 90 78 102
Appending/subsearches can be pretty expensive in terms of performance and sometimes pretty hard to keep track of. What you probably need here is to run a single search over the last 5 weeks (or days, or whatever your window is) BUT scope it to the right hour interval. For example, this search will go back 5 days, search only between 9pm and 10pm and chart the count of events per method
(GET or POST) for said slot of each day:
index=_internal source=*access* date_hour=21 earliest=-5d | chart count over method by date_mday
You could run five subsearches appended to each other, with one set to the one hour you're looking for each week.
Sure. This looks for the count of events in _internal for the past hour plus the same time in the past few weeks:
index=_internal earliest=-h | stats count | addinfo | append [search index=_internal earliest=-w-h latest=-w | stats count | addinfo] | append [search index=_internal earliest=-2w-h latest=-2w | stats count | addinfo] | append [search index=_internal earliest=-3w-h latest=-3w | stats count | addinfo] | append [search index=_internal earliest=-4w-h latest=-4w | stats count | addinfo] | fieldformat info_max_time = strftime(info_max_time, "%+") | fields count info_max_time
Thanks Martin. Can you please give the example query if you have any as I am not sure how we can give the search time inside the search querty?