I have a lookup file with about 100K events. What I want to do is use timechart (span each day). There is a time field in the lookup called '_time'. I have:
| inputlookup mylookup.csv
| timechart span=1d sum(count)
Can I do this?
So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count
(no need to specify a field if just counting events).
| inputlookup mylookup.csv
| convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
| timechart span=1d count as Daily_Total
So what you want your query to do, show count of entries in the lookup per day or sum of some field's value? If you just want to see how many entries falls into a day, just use function count
(no need to specify a field if just counting events).
| inputlookup mylookup.csv
| convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
| timechart span=1d count as Daily_Total
ah man... thank you somesoni2!
@brdr if your issue is resolved, do accept the answer to mark this question as answered.
You can use timechart command as long as _time field in your lookup has date in epoch format. You can use sum(count) if there is a field count exists in the lookup.
This is what I have. I do have a field called 'count' in my lookup that I don't care about. Here is my search:
| inputlookup mylookup.csv
| convert timeformat="%Y-%m-%dT%H:%M:%S" mktime(_time) as _time
| rename count as count_c
| timechart span=1d sum(count) as Daily_Total
I see that _time is display the days, but Daily_Total is NULL (blank)??