Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
splunk query tricks

splunk notes


index=* | stats count user
index=* | stats count by user method version
index=* user="adm*"|stats count by user method version
index=* NOT user="-"|stats count by user method version
index=* NOT user="-" method=get|stats count by user method version

index=* user="*"| timechart count by user
index=* method=* NOT method=get |timechart copunt by method

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.