Beruflich Dokumente
Kultur Dokumente
Commands Covered
Example
Description
Controls which field extractions are performed
multikv
mvcombine
mvcombine mailto
Module 2
stats
top
rare
eventstats
rare mailfrom
eventstats sum(price) as sales
addtotals
addcoltotals
Module 3
eval
where
Module 4
chart
timechart
bucket
table
rename
rex
sort
rangemap
overlap
Commands
Covered
Description
Combines events into a single event (transaction) if they have the same field
values and occur in the specified time range
Performs the http_lookup using the status field as input. Retrieves the
status_descr field.. Requires that the lookup table and lookup fields have already
been defined
Used to generate data that will be placed in a summary index.
For each command, creates an event that contains the appropriate intermediate
results, so that the final calculation can be performed.
Finds any overlapping events in a summary index
Description
Counts the number of events that have the field named; if no field named, counts all the events
Counts the number of unique values for the field named
Sums the values of the field named
Averages the values of the field named; avg(field) = sum(field) / count(field)
Returns the lowest value of the field across all the events
Returns the highest value of the field across all the events
Lists the value of the field for every event
Lists the unique values of the field across all the events
Description
Returns the absolute value of the field
cidrmatch("123.128.32.0/25",ip) Returns true if the second argument is an ip address in the subnet defined by the first
argument
if(status == 200, "OK", "Error") Evaluates the first argument as a Boolean expression. If true, returns the second
argument. If false, returns the third argument.
match(field, regex) Returns true if the value of the field matches the regular expression; otherwise returns false
round(field, n) rounds the value of field to n decimal points
tostring(field,"commas") Rounds the value of the field to 2 decimal points and inserts commas, e.g. 99,999.99
Note: This is not a complete list of commands or functions! For the complete list, see the Splunk Search Reference Manual at
http://www.splunk.com/base/Documentation/latest/SearchReference