Hi,
I'm tryin to get the number of alerts by day.
When i have alerts i see the number in statistics. But when i don't received errors in a day. i don't see the _time value of this day.
For example we are the 2019-04-23. My last alert was the 2019-04-17. I want to see :
_time count
2019-04-17 9
2019-04-18 0
2019-04-19 0
2019-04-20 0
2019-04-21 0
2019-04-22 0
2019-04-23 0
The following search works for me :
index=main earliest="01/01/2019:00:00:00"| ... | append [| streamstats count | eval count=0] | timechart span=1d count
The following search works for me :
index=main earliest="01/01/2019:00:00:00"| ... | append [| streamstats count | eval count=0] | timechart span=1d count
If you use timechart
, by default, it creates empty buckets. Many other commands have a makecontinuous=true
argument to do the same thing. We cannot help better because you did not give us your search SPL.