Avatar

Graham Watts

  • Total activity 106
  • Last activity
  • Member since
  • Following 0 users
  • Followed by 1 user
  • Votes 0
  • Subscriptions 64

Activity overview

Latest activity by Graham Watts
  • Avatar

    Graham Watts commented,

    Official comment

    Hey Soumya,You can plot both series in one table like this: (_sourceCategory=app1 or  _sourceCategory=app2) "HTTP/1.1 500" | count by _sourceCategory| sort _count You could also plot these over ti...

  • Avatar

    Graham Watts commented,

    Hi Sagan, You can use our new feature, Ingest Budgets, to apply a limit of collection per collector. This assumes you have an Enterprise Sumo subscription. Let us know if this is what you are looki...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey David,Can you try this query and let us know if this is what you're trying to see? _sourceCategory=prod/network| count by _sourceHost // assuming these are the source IPs| count by _sourceHost ...

  • Avatar

    Graham Watts commented,

    Hey Ramakrishna,Are you trying to show the trend in percent of 400s? If so you could use something like this: _sourceCategory=graham/travel/nginx| parse "HTTP/1.1\" * " as sc nodrop| if(sc matches ...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Aakif,Parse regex multi will allow you to parse out as many values for LoadBalancerName as there are in each log:https://help.sumologic.com/05Search/Search-Query-Language/01-Parse-Operators/02-...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Alex,Transactionize can be very useful especially in this type of use case. Another way to get the duration is to use max() and min(), then do some math by each trace-id:| max(_messagetime), mi...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Eliezer,I would suggest 2 options here: 1. Consider using Carbon2 metrics format Depending on what is generatin the metric, that tool may have an option to do this Carbon2 format allows you to...

  • Avatar

    Graham Watts commented,

    Hey Ravi,Seems like there are 2 options here: Collect the data in Sumo and query it there- Where is the data coming from? If its already in S3 or CloudWatch log groups you can use native Sumo sour...

  • Avatar

    Graham Watts commented,

    Official comment

    Hello Team Romania,We are currently building a Content API that will allow you to create dashboards automatically via API calls.If you don't mind, please vote and comment at the link below so that ...

  • Avatar

    Graham Watts commented,

    Official comment

    Hey Felipe,You'll need to use the timeslice operator to create a trend over time, you might try something like the below query to take the average of the effectiveness value in 5 minute increments ...