Splunk Search

How to write Stats count by hourly trend list?

corehan
Explorer

Hello dears,

Can i list search result with stat count like hourly trend ?

Example;

Hour : 00:00 EventCount: 10

Hour : 01:00 EventCount: 15

Hour : 02:00 EventCount: 23

.

.

Hour : 23:00 EventCount : 127

Regards.

Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can make trend lines on this sort of data. Are you looking to display a timechart and a trend or how do you want to visualise it?

This is an example that calcualates 24 randomly increasing values and then calculates the rolling 8 hour average trend and plots two lines on a line chart.

| makeresults count=24
| streamstats c
| eval count=(c)*((random()%c/10)+1)
| eval _time=now()-(3600*(24-c))
| streamstats window=8 avg(count) as trend
| fields - c

It uses streamstats to do the trend calculation

 

0 Karma

corehan
Explorer

I'm creating a report ( save as search results as a Report) and scheduling "send mail" like inline table, if it not possible may be attached file fine for me.

Regards.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

So, if you want to show a table with a trend, how do you want to represent your trend? The example I gave shows you a trend of a rolling 8 hour average - you could use that or adjust it to your use case.

 

0 Karma

corehan
Explorer

I want count events for each hour so i need the show hourly trend in table view. Regards.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

so, following on from your example data

Hour : 00:00 EventCount: 10
Hour : 01:00 EventCount: 15
Hour : 02:00 EventCount: 23
.
.
Hour : 23:00 EventCount : 127

do you want the 'trend' for 01:00 to show the difference (+5) to the previous hour and the same for 02:00 (+8) or as a percentage?

Anyway to simply calculate hourly differences, use any of 

  • delta
  • autoregress
  • streamstats (as in my example)

 

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...