view results for last 24 hours, by hourly bases



    Hi Dekel,

    Yes indeed you can achieve the same by using "_timeslice" operator in your query so you can create bucketed results based on a fixed interval (hourly in your case)

    Query should be something like

      * | timeslice 1h
        | count by _timeslice

    Please check below KB article for more example on the same:

    Hope that helps!!






    Hi Rahul,

    thanks for the fast response, that seems to be exactly what i'm looking for :)  dont know how i missed it!


