I am searching IIS logs, trying to calculate the number of GB transferred each day for the last 7 days. Here is my search:
index=iis sourcetype=iis cs_user_agent="JTDI*" earliest=-7d@d | stats sum(cs_bytes) as UPLOADS, sum(sc_bytes) as DOWNLOADS by date_mday | eval UPLOADS=round(UPLOADS/1024/1024/1024,2) | eval DOWNLOADS=round(DOWNLOADS/1024/1024/1024,2) | rename date_mday as "Day of the Month"| sort -"Day of the Month"
The problem I am having is that I get a different result for the 7th day if I use -7d@d vs -8d@d. In both cases, every day should be the total for that day since midnight. So when I search over 8 days, why does my 7th day have more data?