I am trying to construct a historical syslog report with counts of message severity grouped by the hour. I have the data fields that I want except for the time summarization. How can I set that up?
Here's a report I use - hope this helps. The FILTER for 10.16x.x.x is for my own use.
My apologies. That may not be what you want for HOUR summarization. I had one made recently but did not save it. I'll try to recreate it and put it into this thread.
Change your format string in Field Formatting for Date_Time to hh
and group it