My Log data looks like:
i am using this query:
index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" |eval timestamp=strftime(_time, "%F") | chart limit=30 count as count over TransactionType by timestamp
I have to built report on transaction type, total count date wise
please help to form the query,
due to space it is not showing properly
TransactionType = cXML OrderRequest
TransactionType = cXML ConfirmationRequest
Regards
Avik
I presume the problem is the table is very wide. If so, try swapping the terms in the chart command
index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log"
| eval timestamp=strftime(_time, "%F")
| chart limit=30 count as count over timestamp by TransactionType
Alternatively, try the timechart command.
index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log"
| eval timestamp=strftime(_time, "%F")
| timechart useother=0 limit=30 count by TransactionType