Splunk Search

eventcount - spanning over time

brdr
Contributor

I'm attempting to write a search using eventcount command. I want to graph the number of events in my index/sourcetype per day over a span of 1 week. Can I use the eventcount for this? I'm not having much luck.

| eventcount summarize=false index=myindex sourcetype=mysourcetype 
| timechart span=1d count
1 Solution

somesoni2
SplunkTrust
SplunkTrust

The eventcount command just gives the count of events in the specified index, without any timestamp information. Since your search includes only the metadata fields (index/sourcetype), you can use tstats commands like this, much faster than regular search that you'd normally do to chart something like that.

| tstats count WHERE index=myindex sourcetype=mysourcetype by _time span=1d 

You might have to add | timechart span=1d sum(count) as count at the end if the chart doesn't look continuous.

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

The eventcount command just gives the count of events in the specified index, without any timestamp information. Since your search includes only the metadata fields (index/sourcetype), you can use tstats commands like this, much faster than regular search that you'd normally do to chart something like that.

| tstats count WHERE index=myindex sourcetype=mysourcetype by _time span=1d 

You might have to add | timechart span=1d sum(count) as count at the end if the chart doesn't look continuous.

brdr
Contributor

great. thank you.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...