I use the following query against a Cisco as5400 to find the number of calls per hour during a day.
10.200.90.19 Called Number Voice-Interface | timechart span=1h count(Number) | sort - count(Number)
I want to run this query over multiple days and compare the hours over multiple days to tell me the busy hour. I also want to ignore any hours that return a count of zero.
Would this work?
10.200.90.19 Called Number Voice-Interface | timechart span=1h count(Number) as num_count | where num_count > 0 | sort - num_count
date_hour is a default field. You could do:
... earliest=-7d | stats count by date_hour
This is something that you probably don't want to do ad-hoc. I recommend summary indexing: http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Usesummaryindexing
date_hour is a default field. You could do:
... earliest=-7d | stats count by date_hour
This is something that you probably don't want to do ad-hoc. I recommend summary indexing: http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Usesummaryindexing
OK, that did exactly what I wanted. Thanks for the link for summary indexing as well.
Would this work?
10.200.90.19 Called Number Voice-Interface | timechart span=1h count(Number) as num_count | where num_count > 0 | sort - num_count
That got rid of the 0 count events....NICE