Splunk Search
Highlighted

How to use timechart with stats and eval command

Communicator

Hi,

My query is below -

index=abc sourcetype=xyz Unable to connect to the remote server | Stats count(eval("Unable to connect to the remote server")) as "Error" by host

In this query how can I use (timechart span=1h) function? Any suggestions would be appreciated..

Thanks

Tags (3)
0 Karma
Highlighted

Re: How to use timechart with stats and eval command

Esteemed Legend

Your eval is wrong and redundant; try this:

index=abc sourcetype=xyz Unable to connect to the remote server | timechart span=1h count AS "Error" by host

View solution in original post

Highlighted

Re: How to use timechart with stats and eval command

Communicator

thanks... that's cool..

0 Karma