Splunk search for Ingested Comments

Copy
[ | tstats count where punct=#* by index, sourcetype | fields - count | format ] _raw=#*
This search will return comments that have been ingested into Splunk. This search assumes that any event that begins with # is a comment.
0 comments

Category:

Admin


Tags:

data onboarding comments Admin tstats

Search Commands:

Sign in or Register to submit a comment