Splunk Search

How to edit my search to get the max count per hour?

qiaojing
Path Finder

Hi,

I'm trying to get the system with the most number of logs (usage) for every hour. I did a search for:

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string | where maxcount==count

which outputs me a table as shown below.

time               Highest Usage      maxcount 
23/4/2016 0900     system1            10000
23/4/2016 1000     system2            20000
....               .....

However, I hope to get a chart of count over time whereby each bar is maximum count during the 1hr window and each bar has different colors, depending on the type of system. (Currently, all the bars in the chart are the same color, so I don't know what is the corresponding system)

I'm quite new to Splunk Enterprise. Any help will be greatly appreciated.

Thank you!

0 Karma
1 Solution

sundareshr
Legend

See if this gives you what you're looking for

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string System_ID | stats values(System_ID) AS SysID max(maxcount)  as max by date_string 

View solution in original post

sundareshr
Legend

See if this gives you what you're looking for

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string System_ID | stats values(System_ID) AS SysID max(maxcount)  as max by date_string 
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...