在splunk dashboard中想要统计出每小时的event数并做累加,意思就是每个时间点显示的是当前总共的count数:
...(search条件) | timechart span=1h count | streamstats sum(count) as cumulative | fields _time cumulative
在splunk dashboard中想要统计出每小时的event数并做累加,意思就是每个时间点显示的是当前总共的count数:
...(search条件) | timechart span=1h count | streamstats sum(count) as cumulative | fields _time cumulative