index=* | stats count user
index=* | stats count by user method version
index=* user="adm*"|stats count by user method version
index=* NOT user="-"|stats count by user method version
index=* NOT user="-" method=get|stats count by user method version
index=* user="*"| timechart count by user
index=* method=* NOT method=get |timechart copunt by method
Created
April 30, 2019 10:00
-
-
Save tuxfight3r/5f6b0c2d096fc963bfbdfbd72e4fded6 to your computer and use it in GitHub Desktop.
splunk query tricks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment