Splunk Search

How to write Stats count by hourly trend list?

corehan
Explorer

Hello dears,

Can i list search result with stat count like hourly trend ?

Example;

Hour : 00:00 EventCount: 10

Hour : 01:00 EventCount: 15

Hour : 02:00 EventCount: 23

.

.

Hour : 23:00 EventCount : 127

Regards.

Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can make trend lines on this sort of data. Are you looking to display a timechart and a trend or how do you want to visualise it?

This is an example that calcualates 24 randomly increasing values and then calculates the rolling 8 hour average trend and plots two lines on a line chart.

| makeresults count=24
| streamstats c
| eval count=(c)*((random()%c/10)+1)
| eval _time=now()-(3600*(24-c))
| streamstats window=8 avg(count) as trend
| fields - c

It uses streamstats to do the trend calculation

 

0 Karma

corehan
Explorer

I'm creating a report ( save as search results as a Report) and scheduling "send mail" like inline table, if it not possible may be attached file fine for me.

Regards.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

So, if you want to show a table with a trend, how do you want to represent your trend? The example I gave shows you a trend of a rolling 8 hour average - you could use that or adjust it to your use case.

 

0 Karma

corehan
Explorer

I want count events for each hour so i need the show hourly trend in table view. Regards.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

so, following on from your example data

Hour : 00:00 EventCount: 10
Hour : 01:00 EventCount: 15
Hour : 02:00 EventCount: 23
.
.
Hour : 23:00 EventCount : 127

do you want the 'trend' for 01:00 to show the difference (+5) to the previous hour and the same for 02:00 (+8) or as a percentage?

Anyway to simply calculate hourly differences, use any of 

  • delta
  • autoregress
  • streamstats (as in my example)

 

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...