Splunk Search

eventcount - spanning over week

brdr
Contributor

I'm attempting to write a search using eventcount command. I want to graph the number of events in my index/sourcetype per day of a span of week. Can I use evencount for this? I'm not having much luck.

| eventcount summarize=false index=myindex sourcetype=mysourcetype | timechart span=1d count
Tags (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...