Hello Team,
Could you please suggest on how to create an overlapping graph which compares this week's data and previous week's data excluding weekends.
Any help is very much appreciated.
My base search is very simple.
index=my index source=/.log '#search string#'
| time chart span=1h count(_raw) by host
Repeat the first two lines - timechart adds the times back in, but the good thing about it is that if there are any hours without any events, you still get zeroes for those hours. If you use chart or stats instead, the times without events don't appear at all.
Greatt! Thank you so muchh for your help 🙂
| eval day= strftime(_time,"%w")
| where day > 0 AND day < 6
| timechart span=1h count by host
| timewrap 1w align=end
Hello,
Thank you so so much , it works like a charm.
But I still get weekends in the results, is there a way to exclude them?
Repeat the first two lines - timechart adds the times back in, but the good thing about it is that if there are any hours without any events, you still get zeroes for those hours. If you use chart or stats instead, the times without events don't appear at all.