try
index=DBG_SYS sourcetype=DBG_SYS msg="Shelf 1 congestion, resource cps level 2."
| append
[| search index=DBG_SYS sourcetype=DBG_SYS
| regex msg="Shelf 1 slot\s(\d{1,2})\scongestion, resource cpu level\s(\d{1,2})" ]
| rex field=msg "cpu level+\s(?<level>\d+)"
| rex field=msg "cps level+\s(?<level>\d+)"
| where level>0
| eval local_date_hour=strftime(_time,"%H")
| stats by local_date_hour host msg
| table local_date_hour host msg count(code)
| rename count(code) as hits
| rename local_date_hour as Hour
| sort by Hour
... View more