Hi, I am new to splunk.
I would like to generate a report that just list all records which certain criteria e.g. status='success' and list the time stamp and 'userid' field.
Time Userid
1 7/10/13 12:00:00.000 AM daveq
2 7/11/13 12:00:00.000 AM julesx
3 7/12/13 12:00:00.000 AM janeo
....
....
status=success | table _time userid
index=my_index status=success | stats count by _time, Userid | fields _time, Userid
If you all events, then don't dedup userID and table it:
index=my_index status=success | table _time,userID
If you don't want a count, then dedup userID and table it:
index=my_index status=success | dedup userID | table _time,userID