Hello ,
I'm looking for assistance with an SPL search utilizing the tstats command that I can group over a specified amount of time for each of my indexes
I have this command to view the entire ingestion but how can I parse it to show each index?
| tstats count where sourcetype=* by _time span=1d
thank you
Try this: | tstats count where sourcetype=* by index _time span=1d | timechart sum(count) by index
Try this: | tstats count where sourcetype=* by index _time span=1d | timechart sum(count) by index
that is complete awesomeness ! thank you....