I'm trying to format the query in the search bar so it appears on multiple lines (for easier readability).
From this:
sourcetype=iis cs_host="test.com" NOT c_ip="92.111*" | timechart span=1d dc(cs_username) AS User_Count | eval Date=strftime(_time, "%Y-%m-%d") | eval User_Count=tostring(User_Count, "commas") | rename User_Count as "User Count" | table Date, "User Count"
To this:
sourcetype=iis cs_host="test.com" NOT c_ip="92.111*"
| timechart span=1d dc(cs_username) AS User_Count
| eval Date=strftime(_time, "%Y-%m-%d")
| eval User_Count=tostring(User_Count, "commas")
| rename User_Count as "User Count"
| table Date, "User Count"
Is there a shortcut key that will work to split the query into multiple lines? Pressing Enter in the search bar just runs the search.
Thank you.
That worked - thank you!!
Glad to hear it. Feel free to mark it as the answer so other people know that this question has been answered.
Pressing "Shift-Enter" works for me.
If you are using newer version of Splunk, then Ctrl + \