mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
tighten up search timeframe
This commit is contained in:
@@ -74,7 +74,7 @@ for index in $indexes; do
|
|||||||
size_24h_ago=${size_24h_ago:-$current_size}
|
size_24h_ago=${size_24h_ago:-$current_size}
|
||||||
|
|
||||||
size_7d_query="from(bucket: \"telegraf/so_long_term\")
|
size_7d_query="from(bucket: \"telegraf/so_long_term\")
|
||||||
|> range(start: -8d, stop: -6d)
|
|> range(start: -7d8h, stop: -7d)
|
||||||
|> filter(fn: (r) => r._measurement == \"elasticsearch_index_size\" and r._field == \"$index\")
|
|> filter(fn: (r) => r._measurement == \"elasticsearch_index_size\" and r._field == \"$index\")
|
||||||
|> last()
|
|> last()
|
||||||
|> keep(columns: [\"_value\"])"
|
|> keep(columns: [\"_value\"])"
|
||||||
@@ -83,7 +83,7 @@ for index in $indexes; do
|
|||||||
size_7d_ago=${size_7d_ago:-$current_size}
|
size_7d_ago=${size_7d_ago:-$current_size}
|
||||||
|
|
||||||
size_30d_query="from(bucket: \"telegraf/so_long_term\")
|
size_30d_query="from(bucket: \"telegraf/so_long_term\")
|
||||||
|> range(start: -31d, stop: -29d)
|
|> range(start: -30d8h, stop: -30d)
|
||||||
|> filter(fn: (r) => r._measurement == \"elasticsearch_index_size\" and r._field == \"$index\")
|
|> filter(fn: (r) => r._measurement == \"elasticsearch_index_size\" and r._field == \"$index\")
|
||||||
|> last()
|
|> last()
|
||||||
|> keep(columns: [\"_value\"])"
|
|> keep(columns: [\"_value\"])"
|
||||||
|
|||||||
Reference in New Issue
Block a user