The stats command is a transforming command so it discards any fields it doesn't produce or group by. Access timely security research and guidance. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. This function returns a subset field of a multi-value field as per given start index and end index. I did not like the topic organization Search the access logs, and return the total number of hits from the top 100 values of "referer_domain", 3. to show a sample across all) you can also use something like this: That's clean! Returns the chronologically latest (most recent) seen occurrence of a value of a field X. In the table, the values in this field become the labels for each row. Have you tried this: (timechart uses earliest and latest (info_min_time and info_max_time respectively) and should fill in the missing days automatically). A transforming command takes your event data and converts it into an organized results table. The
splunk stats values function
- Posted on: March 10, 2023
- Under: abc north coast presenters
- By:
- With: how did john dillinger get caught