view results for last 24 hours, by hourly bases



  • Avatar
    Rahul Choudhary

    Hi Dekel,

    Yes indeed you can achieve the same by using "_timeslice" operator in your query so you can create bucketed results based on a fixed interval (hourly in your case)

    Query should be something like

      * | timeslice 1h
        | count by _timeslice

    Please check below KB article for more example on the same:

    Hope that helps!!






    Comment actions Permalink
  • Avatar
    Dekel Moyal

    Hi Rahul,

    thanks for the fast response, that seems to be exactly what i'm looking for :)  dont know how i missed it!


    Comment actions Permalink

Please sign in to leave a comment.