当我收到文件时,我有以下日志。
2017-05-20T06:43:18,273 + 0000 LogLevel =" INFO" ThreadId =" [ACTIVE] ExecuteThread:' 1' for queue:' weblogic.kernel.Default(自我调整)'" ServerName =" ServerName"的requestId =" 123456" EVENTCODE =" POSTDATA" EventMessage =" Checksum成功验证输入文件:myfileName100"
Splunk查询:index =" myindex" "校验和成功验证输入文件:" 现在我想使用splunk查询每小时获得上述事件的计数。请帮忙
答案 0 :(得分:2)
试试这个
index=<index-name> EventMessage="Checksum validated successfully*" | timechart count span=1h