Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

What is the difference between the dbinspect command and "_bkt"?

$
0
0
Hello guys, Could you let me know the difference in terms of buckets between : `| dbinspect *search* and *search* | eval bkt=_bkt | table bkt` ? It looks like `dbinspect` returns more results and with a wider span. My aim is to remove buckets according to a specific search and timeframe. Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>