Compare periods
compare_periodsCompare two Graylog log periods (default last hour vs prior) to surface new, increased, gone, or decreased error groups normalized per hour.
Instructions
Compare two periods (default: last window vs the one before; or around split_at). Lists groups that are new, increased, gone or decreased, normalised per hour. Defaults to errors only.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Groups to return | |
| query | No | Extra Lucene filter | |
| window | No | Length of each period when using split_at or the default | 1h |
| streams | No | Stream titles or ids to search in; all streams when omitted | |
| group_by | No | 'exception', 'logger', 'source' or any field | exception |
| instance | No | Graylog instance (environment) from list_instances, e.g. 'staging' or 'prod'; the default instance when omitted | |
| split_at | No | Point in time (e.g. a deploy); compares [split-window, split] with [split, split+window] | |
| current_to | No | Explicit current period end; default now | |
| baseline_to | No | Explicit baseline end | |
| errors_only | No | AND the configured error query (default true) | |
| current_from | No | Explicit current period start | |
| baseline_from | No | Explicit baseline start |