I have a search like below -
mysearch | timechart count span=1h | timewrap 1d
with time range picker for past 7 days. This search fetches all the records for past 7 days with records falling in same Timerange.
But I want to compare the current hour count with last week same day/hour count. And skip timewrap to fetch for remaining 6 days.
In the End of the search I can put a table and fetch only today and 6_days_before columns, but 6 days count fetching is taking lot of time. Rather if we can restrict to fetch only for Present Day and 6 days before, it will be faster.
Any suggestions ?
Try the following:
<your base search> earliest=-7d@d latest=-6d@d | append [search <your base search again> earliest=@d latest=now()] | timechart span=1h count | timewrap 1d
This should leave out all the non-desired days...
Try the following:
<your base search> earliest=-7d@d latest=-6d@d | append [search <your base search again> earliest=@d latest=now()] | timechart span=1h count | timewrap 1d
This should leave out all the non-desired days...
Thank you. Will this have the restriction of SubSearch ? (50K)
Yes it will by default, but you may use the command parameters maxout
and maxtime
for tuning the returned results of the subsearch.