- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I'm doing a device count based on device latest time event registration. I'm getting the correct device registration count here on a single value (ex. 1000 count) filed but with no trending:
index.... ... earliest=-1mon
| stats count latest(_time) as last_update by device_name EventType
| search EventType="Registered"
| stats count(device_name) as Device_Count by last_update
I would like create a single value visualization to show trend of device registration compared to 2 weeks ago count. I tried the following but I'm not getting the same count as my device registration.
index.... ... earliest=-1mon
| stats count latest(_time) as last_update by device_name EventType _time
| search EventType="Registered"
| stats count(device_name) as Device_Count by last_update
| timechart span=2w count(Device_Count)
How can I fix this to show trend of the correct count of registered devices compared to 2-weeks ago?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@alc2019,
Try
index.... ... earliest=-1mon EventType="Registered"
| timechart span=2w count(device_name) as device_count
What goes around comes around. If it helps, hit it with Karma 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@alc2019,
Try
index.... ... earliest=-1mon EventType="Registered"
| timechart span=2w count(device_name) as device_count
What goes around comes around. If it helps, hit it with Karma 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Renjith,
Thanks for the help but it will not work on my case as those devices register multiple times in a day and I have to count the registration based on their latest registration time.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@alc2019,
What about
index.... ... earliest=-1mon EventType="Registered"
|stats latest(_time) as _time by device_name
| timechart span=2w count(device_name) as device_count
What goes around comes around. If it helps, hit it with Karma 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perfect - works!
Thank you
