Count Number of Events By Host

Comments

1 comment

  • Avatar
    Raghu Murthy

    Hi Garland,

    You would need to use the transpose operator to specify the row to be time and column as number of events by hosts.

    http://help.sumologic.com/Help/Default.htm#Transpose_Operator.htm

    Your query would be like this

    _sourceCategory=prod-upcode 

    | parse regex "^\w+\s+\d+\s\d+:\d+:\d+\s(?<aHost>\w+-\w+-\w+-\w+-\w+)"

    | timeslice by 5m

    | count_distinct(_raw) by _timeslice, aHost

    | transpose row _timeslice column aHost

    Hope this helps

    thanks

    Raghu 

     

     

    0
    Comment actions Permalink

Please sign in to leave a comment.