[ | tstats count where punct=#* by index, sourcetype | fields - count | format ] _raw=#*
0 comments
[ | tstats count where punct=#* by index, sourcetype | fields - count | format ] _raw=#* | eval gb=len(_raw)/pow(1024,3) | timechart span=1d sum(gb)
0 comments
index=_internal sourcetype=splunkd group=search_concurrency name=search_queue_metrics | timechart avg(current_queue_size)
0 comments
index=_audit action=edit_user operation=create |rename object as user |eval timestamp=strptime(timestamp, "%m-%d-%Y %H:%M:%S.%3N") |convert timeformat="%d/%b/%Y" ctime(timestamp) |table user timestamp
0 comments
index=_audit action=search info=completed search_et="N/A" search_lt="N/A" user!=splunk-system-user | stats count by user
0 comments
index=_internal tcpouteloop "connected to idx" | stats count by idx
0 comments
| rest splunk_server=local /servicesNS/-/Splunk_SA_CIM/data/models | fields title eai:data | spath input=eai:data path=objects{}.fields{} output=fields | mvexpand fields | spath input=fields | fields - eai:data fields
0 comments
| rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_connections | search [ | rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_inputs | search disabled=0 | stats count by connection | fields - count | rename connection as title | format ] | table title connection_type database host identity port
0 comments
| rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_inputs
0 comments
| rest splunk_server=local /services/server/info | table splunk_server numberOfCores numberOfVirtualCores os_build physicalMemoryMB | appendcols [| rest splunk_server=local /services/server/status/partitions-space | table splunk_server mount_point available capacity ] | eval freeDiskGB=available/1024, totalDiskGB=capacity/1024 | table splunk_server numberOfCores numberOfVirtualCores os_build physicalMemoryMB mount_point freeDiskGB totalDiskGB | addcoltotals freeDiskGB totalDiskGB
0 comments