Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how do I cause summary indexing keep stats on distinct items?

$
0
0
I am having trouble understanding summary indexing, and keeping stats on container objects, but I am really interested on the stats on distinct objects in the containers. How do I cause summary indexing to keep stats on the distinct items? Lets say I am an internet service provider (ISP) and I provide IP addresses that are grouped by network, and I wish to count addresses in use. I would summarize as follows: index=blah | fields ip | eval age_category=case(_timerelative_time(now(), "-60d@d") AND _timerelative_time(now(), "-30d@d") AND _time

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>