Hi there, I have this query:
index=_internal source="*license_usage.log"
| eval bytes=b
| eval GB = round(bytes/1024/1024/1024,3)
| timechart span=1d sum(GB) by h
This query shows results like this:
_time | host1 | .... |
2023-11-10 | ||
2023-11-11 | ||
... |
And I want results like this:
Host | 2023-11-10 | .... |
host1 | ||
host2 | ||
... |
How I can do this?
Hi @Zodi_6 ,
see the transpose command at https://docs.splunk.com/Documentation/Splunk/9.1.2/SearchReference/Transpose and, please, try:
index=_internal source="*license_usage.log"
| eval bytes=b
| eval GB = round(bytes/1024/1024/1024,3)
| timechart span=1d sum(GB) by h
| transpose 0 column_name=h header_field_time
Ciao.
Giuseppe
Use chart.
index=_internal source="*license_usage.log"
| eval bytes=b
| eval GB = round(bytes/1024/1024/1024,3)
| bucket _time span=1d
| eval _time = strftime(_time, "%F")
| chart sum(GB) over h by _time