Splunk技术问询:将1天拆分为两小时间隔统计请求次数
按两小时间隔统计Splunk访问数据
原查询语句
index="dummy" url="https://www.dummy.com" status="200 OK" | stats count by id | where count > 10
原查询1天时间范围的结果
id count ABC 50 XYZ 60 ..
该结果表示ABC在1天内访问https://www.dummy.com共50次,XYZ访问共60次。
统计需求
针对1天时间范围,按每两小时的时间间隔进行统计,输出需包含id、count和对应的时间区间,示例输出如下:
id count time XYZ 60 12:00 AM ABC 25 12:00 AM ABC 25 2:00 AM ..
修改后的Splunk查询
index="dummy" url="https://www.dummy.com" status="200 OK" | bin span=2h _time | stats count by id, _time | where count > 10 | eval time=strftime(_time, "%I:%M %p") | table id, count, time
关键步骤说明
bin span=2h _time:将原始_time字段按2小时跨度分组,生成对应的时间区间stats count by id, _time:同时按id和划分后的时间区间统计访问次数eval time=strftime(_time, "%I:%M %p"):把Splunk时间戳转换为12:00 AM这类可读格式,若需24小时制可改用%H:%M格式table id, count, time:按需求指定输出字段顺序,匹配期望的结果格式
内容的提问来源于stack exchange,提问作者MrRobot9
相关产品推荐
相关产品推荐

