Splunk Search
Highlighted

How to count a sum of events since a specified time?

Explorer

How to count how many events are over 1 yr old? And better yet, how to show a pie chart comparing against the entire list?

0 Karma
Highlighted

Re: How to count a sum of events since a specified time?

SplunkTrust
SplunkTrust

I'm sure there will be other ways to achieve the same. Anyway, try this:

| metasearch index=foo sourcetype=bar
| eval year = relative_time(now(), "-1y")
| eval age = if(_time < year, "old", "new")
| stats count by age

Then go to the visualization tab and select Pie.

View solution in original post

0 Karma
Highlighted

Re: How to count a sum of events since a specified time?

Explorer

Wow-- Never thought of metasearch OR starting with a pipe.. but it works.. Thanks!

0 Karma