Hi all,
I currently have a search that I need a little tweaking to get something else that I want.
So the current search :
index=test sourcetype=test "OOID Folder workspace" | lookup client_ooid_to_name OOID OUTPUT clientName | eval Client=clientName . "(" . OOID . ")" | chart count by Client action | addtotals | sort 5 -Total
Looks up the five most active OOIDs by number, maps them to a name which I imported a lookup table for, then displays the count of actions for each OOID.
What I want to do now is to just get the total number of OOIDS per day, as opposed to finding the count for each one.
Can anyone lend a hand?
Thanks in advance for your responses.
How about this
index=test sourcetype=test "OOID Folder workspace" | timechart span=1d count(OOID) as OOID_Count
OR
index=test sourcetype=test "OOID Folder workspace" | lookup client_ooid_to_name OOID OUTPUT clientName | eval Client=clientName . "(" . OOID . ")"| timechart span=1d count(Client) as OOID_Count
Thanks for your responses guys! All work like a dream!
Perhaps something like this?
index=test sourcetype=test "OOID Folder workspace" | stats dc(OOID) | ...
or maybe
index=test sourcetype=test "OOID Folder workspace" | timechart span=1d dc(OOID) | ...
How about this
index=test sourcetype=test "OOID Folder workspace" | timechart span=1d count(OOID) as OOID_Count
OR
index=test sourcetype=test "OOID Folder workspace" | lookup client_ooid_to_name OOID OUTPUT clientName | eval Client=clientName . "(" . OOID . ")"| timechart span=1d count(Client) as OOID_Count
Count gives the number of events with the ooid field. DC is the correct function.