Log histogram
log_histogramCount Graylog messages over time and pinpoint the peak bucket, first/last non-empty buckets, and spike onset to find when a problem began.
Instructions
Message counts over time (exact). Reports the peak bucket, first/last non-empty bucket and the 'onset' of a spike, to find when a problem started.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| query | No | Lucene query, '*' for everything | * |
| range | No | Relative range ending now (or at to_time): '15m', '2h', '1d', '1h30m' | 1h |
| streams | No | Stream titles or ids to search in; all streams when omitted | |
| to_time | No | Absolute end, same formats as from_time; default now | |
| instance | No | Graylog instance (environment) from list_instances, e.g. 'staging' or 'prod'; the default instance when omitted | |
| interval | No | Bucket size such as '1m', '5m', '1h'; chosen automatically when omitted | |
| from_time | No | Absolute start: ISO 8601 or 'YYYY-MM-DD HH:MM' in the instance timezone; overrides range |