Hi all,
index=ddos device_event_class_id=Bandwidth earliest=-1d@d latest=-0d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="yersterday" | timechart span=3h count by pg_name | append [search index=ddos device_event_class_id=Bandwidth earliest=-2d@d latest=-1d@d | rex field=msg "msg=.+raffic.+'(?<pg_name>[\w\s\-]+)'.+(?<bps>\d+\.\d+\s.+)\..+" | eval ReportKey="beforeyesterday" | timechart span=3h count by pg_name ] | fillnull value=0 | eval mytime=strftime(_time, "%H:%M") | sort mytime |
Thanks in advance.
Try adding:
| timewrap d
Thanks a lot!
Check out the timewrap command.