Thank you for the reply. I put in what wrote and I get "No results found." I am really not sure why that would be. I have 65 devices sending millions of log entries to Splunk. Here is the search that I am using, redacted index=my_index sourcetype=my_sourcetype tstats prestats=t count by _time,host | timechart span=1h count by host When I had the pipe (|) before the tstats it said that tstats needs to be the first item in the search. Thanks again for your help! -Josh
... View more