Chart Log Ingestion by Logger

Comments

2 comments

  • Avatar
    Harishwer Selvakumar

    Hi Nathan,

    Can you try either of the three queries to see if it fits your requirement?

    _index=my_index AND _sourceName="mysource"
    | parse "* * [*] * * [* *] - *" as day, time, thread, log_level, logger, trace_id, span_id, message
    | timeslice 1h
    | count by logger, _timeslice
    | top 10 logger, _timeslice by _count

    OR

    _index=my_index AND _sourceName="mysource"
    | parse "* * [*] * * [* *] - *" as day, time, thread, log_level, logger, trace_id, span_id, message
    | timeslice 1h
    | count by logger, _timeslice
    | transpose row _timeslice column logger

    OR

    _index=my_index AND _sourceName="mysource"
    | parse "* * [*] * * [* *] - *" as day, time, thread, log_level, logger, trace_id, span_id, message
    | timeslice 1h
    | count by logger, _timeslice
    | top 300 logger, _timeslice by _count
    | transpose row _timeslice column logger

    Thank you

    Regards
    Harishwer Selvakumar
    Customer Success Engineer - Sumo Logic
     
    1
    Comment actions Permalink
  • Avatar
    Nathan Norman

    Harishwer Selvakumar thank you very much for your response. 

    The second two queries are exactly what I was looking for. This will be very helpful for my team to figure out where our excess log volume is originating from. Thanks again.

    0
    Comment actions Permalink

Please sign in to leave a comment.