- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sonicZ
Contributor
10-01-2014
04:36 PM
I have a chart command i've been gathering all the netstat values for a single hour
index=os host=ship* starttime=10/01/2014:19:00:00 endtime=10/01/2014:19:20:00 sourcetype=netstat | multikv fields State AS netstat_states | chart count by State, host
Trying to get the equivalent timechart values so I can see when certain states occurred.
here's what i have so far but does not get the actual netstat states, just the count. Looking to get the actual netstat values captured in the timechart as well.
index=os host=ship* sourcetype=netstat | multikv fields State as netstat_states | timechart span=1h count(netstat_states) by host
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1b197/1b197b09c45bbfae72b1198f045addd16a8a2cdb" alt="lguinn2 lguinn2"
lguinn2
Legend
10-01-2014
05:00 PM
Try this...
index=os host=ship* starttime=10/01/2014:19:00:00 endtime=10/01/2014:19:20:00 sourcetype=netstat
| multikv fields State AS netstat_states
| eval State_host = State . "+" . host
| timechart count by State_host
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1b197/1b197b09c45bbfae72b1198f045addd16a8a2cdb" alt="lguinn2 lguinn2"
lguinn2
Legend
10-01-2014
05:00 PM
Try this...
index=os host=ship* starttime=10/01/2014:19:00:00 endtime=10/01/2014:19:20:00 sourcetype=netstat
| multikv fields State AS netstat_states
| eval State_host = State . "+" . host
| timechart count by State_host
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sonicZ
Contributor
10-02-2014
02:15 PM
That was it, will be very useful for timecharting other multikv stats, I had to use a limit=0 but got what i needed with your search. Thanks
data:image/s3,"s3://crabby-images/5d9f8/5d9f80c54160124d38856b77a799077db7d57026" alt=""