Splunk Search

How to edit my search to get the max count per hour?

qiaojing
Path Finder

Hi,

I'm trying to get the system with the most number of logs (usage) for every hour. I did a search for:

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string | where maxcount==count

which outputs me a table as shown below.

time               Highest Usage      maxcount 
23/4/2016 0900     system1            10000
23/4/2016 1000     system2            20000
....               .....

However, I hope to get a chart of count over time whereby each bar is maximum count during the 1hr window and each bar has different colors, depending on the type of system. (Currently, all the bars in the chart are the same color, so I don't know what is the corresponding system)

I'm quite new to Splunk Enterprise. Any help will be greatly appreciated.

Thank you!

0 Karma
1 Solution

sundareshr
Legend

See if this gives you what you're looking for

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string System_ID | stats values(System_ID) AS SysID max(maxcount)  as max by date_string 

View solution in original post

sundareshr
Legend

See if this gives you what you're looking for

eventtype="centralizedlog" | bin span=1h _time | eval date_string=strftime(_time,"%d/%m/%y %H:%M:00") | stats count as count by date_string, System_ID |eventstats max(count) as maxcount by date_string System_ID | stats values(System_ID) AS SysID max(maxcount)  as max by date_string 
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...