You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk技术问询:将1天拆分为两小时间隔统计请求次数

按两小时间隔统计Splunk访问数据

原查询语句

index="dummy" url="https://www.dummy.com" status="200 OK"  
| stats count by id 
| where count > 10

原查询1天时间范围的结果

id            count
ABC             50
XYZ             60
..

该结果表示ABC在1天内访问https://www.dummy.com共50次,XYZ访问共60次。

统计需求

针对1天时间范围,按每两小时的时间间隔进行统计,输出需包含id、count和对应的时间区间,示例输出如下:

id            count    time
XYZ             60   12:00 AM
ABC             25   12:00 AM
ABC             25   2:00 AM
..

修改后的Splunk查询

index="dummy" url="https://www.dummy.com" status="200 OK"
| bin span=2h _time
| stats count by id, _time
| where count > 10
| eval time=strftime(_time, "%I:%M %p")
| table id, count, time

关键步骤说明

  • bin span=2h _time:将原始_time字段按2小时跨度分组,生成对应的时间区间
  • stats count by id, _time:同时按id和划分后的时间区间统计访问次数
  • eval time=strftime(_time, "%I:%M %p"):把Splunk时间戳转换为12:00 AM这类可读格式,若需24小时制可改用%H:%M格式
  • table id, count, time:按需求指定输出字段顺序,匹配期望的结果格式

内容的提问来源于stack exchange,提问作者MrRobot9

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 06:50:45