Hello All,
I was extracting some volume data for PE testing from prod systems, using following query
I am expecting to get stats from 9AM to 6PM event counts with respect to proxy names. but following code creating stats for entire day please help me to remove these extra data.
Query
index= index_Name environmentName= Env_name clientAppName="App_Name"
| eval eventHour=strftime(_time,"%H")
| where eventHour<18 AND eventHour>=9
| timechart count span=60m by proxyName
result :
TIme | Proxy1 | proxy2 |
2022-02-16 06:00 | 0 | 0 |
2022-02-16 07:00 | 0 | 0 |
2022-02-16 08:00 | 0 | 0 |
2022-02-16 09:00 | 27 | 34 |
Hi @shreem,
the bins in timechart are the ones in the time period you defined, so the easier way is to reduce the time period.
Otherwise, you should filter results after the time chart:
index= index_Name environmentName= Env_name clientAppName="App_Name"
| timechart count span=60m by proxyName
| eval eventHour=strftime(_time,"%H")
| where eventHour<18 AND eventHour>=9
| fields - eventHour
Ciao.
Giuseppe
Thanks for quick response, it worked!!!
Hi
@shreem as the proposed solutions is working, please accept it as solution, so other people can see that it works.
Happy splunking.
r. Ismo
Hi @shreem,
the bins in timechart are the ones in the time period you defined, so the easier way is to reduce the time period.
Otherwise, you should filter results after the time chart:
index= index_Name environmentName= Env_name clientAppName="App_Name"
| timechart count span=60m by proxyName
| eval eventHour=strftime(_time,"%H")
| where eventHour<18 AND eventHour>=9
| fields - eventHour
Ciao.
Giuseppe