Thanks for replying Rick, Running the following: index=Network dest_ip=xx.xx.xx.xx. action=allowed | bin span=1d | stats count by src_ip _time Returns the following error: Error in 'bin' command: You must specify a field to discretize. Not looking to list the source IP's, just need counts per day so have tried using: index=Network dest_ip=xx.xx.xx.xx. action=allowed | bin _time span=1d | stats count by _time Reading this as when the condition (index=Network dest_ip=xx.xx.xx.xx. action=allowed) has been met, break up time into 1 day Bins (bin _time span=1d ) and list total count of each time this condition is met for each Bin which is one day. Am I on the right track here?
... View more