Hi @all,
I'm a little bit helpless at the beginning of SPLUNK.
I tried to do simple queries like:
Both commands doesn't work. Can you please help me finding and execute the right commands?
Thank you 🙂 BR Michael
In both cases:
index=name http_status=200 | timechart count
Just change cs_uri_stem before pipe.
R. Ismo
Thanks for your help 🙂
You should only pass a field into your function, you're passing a field and its value. So for the first one, it would look like
index="name" http_status=200 | timechart count
Second one should work since you're passing a field. Verify the field is spelled right and in the timerange of your data
In both cases:
index=name http_status=200 | timechart count
Just change cs_uri_stem before pipe.
R. Ismo