How does this look?
| tstats count AS hourlyCount WHERE earliest=-7d@d index=* by index, _time span=1h | eval now_hour=strftime(now(),"%H") | eval time_hour=strftime(_time,"%H") | where time_hour=now_hour
| eventstats avg(hourlyCount) as AverageCountPerDay stdev(hourlyCount) as StdDev by index | where hourlyCount<AverageCountPerDay-(2*StdDev) | table _time, index, hourlyCount, AverageCountPerDay, StdDev
Going back one week, looking for that specific hour and comparing those times.
... View more