Exchange 2010, Log Parser, Windows Event Logs, CSV File Format.
Posted on 2014-02-03
Hoping for some query assistance here. I am using log parser to read a bung of events from several different servers all dumped into 1 CSV file.
So far everything works correctly. Here is the query i am using:
/* New Query */
SELECT TimeCreated AS TimeCreated, Count (ID) as EventID, LevelDisplayName as Severity
Where Severity LIKE '%Critical%' OR Severity LIKE '%Warning%'
GROUP BY TimeCreated,Severity,ID
Order By TimeCreated Asc
The only problem i have is that each date/time is counted separately, so for example, I get the following:
TimeCreated EventID Severity
1/1/2014 10:01:46 PM 3 Warning
1/1/2014 10:02:36 AM 1 Warning
1/1/2014 10:02:50 PM 1 Warning
1/1/2014 10:15:23 PM 1 Warning
1/1/2014 10:17:37 AM 1 Warning
1/1/2014 10:17:51 PM 1 Warning
1/1/2014 10:18:15 PM 1 Warning
1/1/2014 10:30:29 AM 1 Warning
1/1/2014 10:32:37 AM 1 Warning
1/1/2014 10:32:52 PM 1 Warning
What i want to do is break down the events by day and not by time. So i would want to see all events that occurred on say 1/1/2014, but not further separated by time on that same date.
I am trying to create a graph that shows the number of events for each day of the month. I have tried using the TO_Date(Timestamp) function but its not working for me.
Please note: I need to pull this data from a flat CSV file and not from each server itself.