index=_audit action=search info=completed search_et="N/A" search_lt="N/A" user!=splunk-system-user | stats count by user
0 comments
index=_internal tcpouteloop "connected to idx" | stats count by idx
0 comments
| rest splunk_server=local /servicesNS/-/Splunk_SA_CIM/data/models | fields title eai:data | spath input=eai:data path=objects{}.fields{} output=fields | mvexpand fields | spath input=fields | fields - eai:data fields
0 comments
| rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_connections | search [ | rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_inputs | search disabled=0 | stats count by connection | fields - count | rename connection as title | format ] | table title connection_type database host identity port
0 comments
| rest splunk_server=local /servicesNS/-/splunk_app_db_connect/configs/conf-db_inputs
0 comments
| rest splunk_server=local /services/server/info | table splunk_server numberOfCores numberOfVirtualCores os_build physicalMemoryMB | appendcols [| rest splunk_server=local /services/server/status/partitions-space | table splunk_server mount_point available capacity ] | eval freeDiskGB=available/1024, totalDiskGB=capacity/1024 | table splunk_server numberOfCores numberOfVirtualCores os_build physicalMemoryMB mount_point freeDiskGB totalDiskGB | addcoltotals freeDiskGB totalDiskGB
0 comments
| inputlookup <insert lookup file name> | foreach * [ | eval b_<<FIELD>>=len(<<FIELD>>) + 1 ] | addtotals b_* fieldname=b | stats sum(b) as b | eval mb=b/1024/1024, gb=mb/1024 | fields b mb gb
0 comments
| tstats count where index=* by _time, _indextime, sourcetype | rename _* as * | eval diff_secs=indextime-time, diff_hours=diff_secs/60/60 | stats max(diff_secs) as diff_secs, max(diff_hours) as diff_hours by sourcetype
0 comments
| tstats count where index=* by _time, _indextime, index | rename _* as * | eval diff_secs=indextime-time, diff_hours=diff_secs/60/60 | stats max(diff_secs) as diff_secs, max(diff_hours) as diff_hours by index
0 comments
index=_introspection component=Hostwide | bin _time span=1d | stats values(data.splunk_version) by _time, host
0 comments