Hi Team,
I'm new to Splunk and will need some help in getting this query total sum by timestamp as we are not explicitly
timestamp from code.
|mstats sum(_value) as total WHERE index='abc' | where total>0
Hi @pancham ...
Are you sure about the "_value" ?...it looks like missing some portions.
Example mstats variables:
spl.intr.resource_usage.PerProcess.data.elapsed
os.mem.rss
aws.ec2.CPUUtilization
may we know what happens when you run..
|mstats sum(value) as total WHERE index='abc'