view results for last 24 hours, by hourly bases

Comments

2 comments

  • Avatar
    Rahul Choudhary

    Hi Dekel,

    Yes indeed you can achieve the same by using "_timeslice" operator in your query so you can create bucketed results based on a fixed interval (hourly in your case)

    Query should be something like

      * | timeslice 1h
        | count by _timeslice

    Please check below KB article for more example on the same:
    https://help.sumologic.com/05Search/Search-Query-Language/Search-Operators/timeslice

    Hope that helps!!

     

    -Rahul

     

     

     

    0
    Comment actions Permalink
  • Avatar
    Dekel Moyal

    Hi Rahul,

    thanks for the fast response, that seems to be exactly what i'm looking for :)  dont know how i missed it!

     

    0
    Comment actions Permalink

Please sign in to leave a comment.