Splunk Search

How to count the number of eventts starting at 9 am each day?

auaave
Communicator

Hi Guys,

I have the below query using that is using the shared timepicker: today, which is counting the events from 00:00 to 23:59.
How can I make it to start count the events from 9:00 to 23:59?

| dedup IDEVENT 
| timechart SPAN=1H COUNT AS IDEVENT 
| rename IDEVENT AS " PALLET QUANTITY"

Thanks a lot!

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

hey try this

your_base_Search earliest=@d+9h latest=now 
| dedup IDEVENT 
| timechart SPAN=1H COUNT AS IDEVENT 
| rename IDEVENT AS " PALLET QUANTITY"

let me know if this helps you!

View solution in original post

auaave
Communicator

@ mayurr98 Great! Thanks! It worked! 🙂

0 Karma

mayurr98
Super Champion

you are welcome,
accept and upvote if it works for you!

0 Karma

mayurr98
Super Champion

hey try this

your_base_Search earliest=@d+9h latest=now 
| dedup IDEVENT 
| timechart SPAN=1H COUNT AS IDEVENT 
| rename IDEVENT AS " PALLET QUANTITY"

let me know if this helps you!

micahkemp
Champion

I'm not sure your search in the example makes sense as-is, but perhaps that's due to it being altered for the question. Assuming it's valid, and you want to only include hours after 9am, try this:

<your search> date_hour>=9
| dedup IDEVENT 
| timechart SPAN=1H COUNT AS IDEVENT 
| rename IDEVENT AS " PALLET QUANTITY"

Splunk parses out the timestamp components (date_month, date_mday, date_hour, etc) for each event, so these fields are available to be a part of your base search.

0 Karma

auaave
Communicator

Thanks @micahkemp

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...