index=_internal sourcetype="splunkd" log_level="ERROR" | stats sparkline count dc(host) as uniquehosts last(event_message) as event_message last(_time) as last first(_time) as first by punct | eval last=strftime(last,"%b %d, %Y %H:%M:%S"), first=strftime(first,"%b %d, %Y %H:%M:%S") | table event_message count uniquehosts first last sparkline | sort -count | rename event_message as "Error" count as Count uniquehosts as "Affected Hosts" first as "First Occurance" last as "Most Recent Occurance", sparkline as Trend
index="_internal" source="*metrics.log*" group=tcpin_connections NOT eventType=* | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | search sourceHost=* | timechart per_second(kb) by sourceHost WHERE max in top5 useother=f | rename sourceHost as UF
index="_internal" source="*metrics.log" group="per_sourcetype_thruput" | eval GB=kb/1024/1024 | chart sum(GB) as "GB Ingested" avg(eps) as "Events per Second" over series | eval "GB Ingested"=round('GB Ingested',4), "Events per Second"=round('Events per Second',4) | rename series as Log