Splunk Search

If I want to gather the statistics day by day for seeing the trend of each type of data and for checking the usage of any new data on-board in the future.

ctksplunkctk
New Member

Hi all,
I have search through the questions asked regarding caption question and find below query. If I want to gather the statistics day by day for seeing the trend of each type of data and for checking the usage of any new data on-board in the future.
How should I modify the query?
Thanks for the help in advance.
Ricky

  1. index=_internal source=*license_usage.log type="Usage"
  2. | eval indexname = if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx)
  3. | eval sourcetypename = st
  4. | bin _time span=1d
  5. | stats sum(b) as b by _time, pool, indexname, sourcetypename
  6. | eval GB=round(b/1024/1024/1024, 3)
  7. | fields _time, indexname, sourcetypename, GB
Tags (2)
0 Karma
1 Solution

to4kawa
Ultra Champion
index=_internal source=*license_usage.log type="Usage" 
| eval indexname = if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx) 
| eval sourcetypename = st 
| bin _time span=1d 
| stats sum(b) as b by _time, pool, indexname, sourcetypename 
| eval GB=round(b/1024/1024/1024, 3) 
| fields _time, indexname, sourcetypename, GB
| eval index_sourcetype=indexname.":".sourcetypename
| xyseries _time index_sourcetype GB
| fillnull value=0.000

Hi, @ctksplunkctk
How about this?

View solution in original post

0 Karma

to4kawa
Ultra Champion
index=_internal source=*license_usage.log type="Usage" 
| eval indexname = if(len(idx)=0 OR isnull(idx),"(UNKNOWN)",idx) 
| eval sourcetypename = st 
| bin _time span=1d 
| stats sum(b) as b by _time, pool, indexname, sourcetypename 
| eval GB=round(b/1024/1024/1024, 3) 
| fields _time, indexname, sourcetypename, GB
| eval index_sourcetype=indexname.":".sourcetypename
| xyseries _time index_sourcetype GB
| fillnull value=0.000

Hi, @ctksplunkctk
How about this?

0 Karma

ctksplunkctk
New Member

thanks @to4kawa, its work !

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...