The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by fitzb0z0
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
Top events groupd by device
In: SplunkPreview
(Not tagged)
Thanks, this helped me get closer to what I am looking for.
source="mcevent.csv" | top limit=1 msg ...
Hello, I am running splunk on a alert log from a monitoring system. I have two fields 1) "msg" ... |
2
|
26 months ago... |