Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Using _time as a discriminator without time span?

$
0
0
I want to use the _time field as one of my discriminator fields in a tstats command. I wasn't able to figure out, how to do this, without the time values being rounded/group in some time stamp. For other fields, when used as discriminators every existing value is displayed as a separate row, but with _time, even if I'm no using any span= with my command, they are grouped somehow. Obviously, in this case, I have really rare events, that's why I want to have the exact time values here.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>