Hi,
I'm doing a device count based on device latest time event registration. I'm getting the correct device registration count here on a single value (ex. 1000 count) filed but with no trending:
index.... ... earliest=-1mon
| stats count latest(_time) as last_update by device_name EventType
| search EventType="Registered"
| stats count(device_name) as Device_Count by last_update
I would like create a single value visualization to show trend of device registration compared to 2 weeks ago count. I tried the following but I'm not getting the same count as my device registration.
index.... ... earliest=-1mon
| stats count latest(_time) as last_update by device_name EventType _time
| search EventType="Registered"
| stats count(device_name) as Device_Count by last_update
| timechart span=2w count(Device_Count)
How can I fix this to show trend of the correct count of registered devices compared to 2-weeks ago?
@alc2019,
Try
index.... ... earliest=-1mon EventType="Registered"
| timechart span=2w count(device_name) as device_count
@alc2019,
Try
index.... ... earliest=-1mon EventType="Registered"
| timechart span=2w count(device_name) as device_count
Hi Renjith,
Thanks for the help but it will not work on my case as those devices register multiple times in a day and I have to count the registration based on their latest registration time.
Thanks
@alc2019,
What about
index.... ... earliest=-1mon EventType="Registered"
|stats latest(_time) as _time by device_name
| timechart span=2w count(device_name) as device_count
Perfect - works!
Thank you