O'Reilly logo

Implementing Splunk - Second Edition by James D Miller, Vincent Bumgarner

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Using sistats, sitop, and sitimechart

First, let's define some new functions:

  • Sistats: sistats is the summary indexing version of the stats command, which calculates the aggregate statistics over the dataset.
  • Sitop: sitop is the summary indexing version of the top command, which returns the most frequent value of a field or a combination of fields.
  • Sitimechart: sitimechart is the summary indexing version of the timechart command, which creates a time-series chart visualization with the corresponding table of statistics.

So far, we have used the stats command to populate our summary index. While this works perfectly well, the si* variants have a couple of advantages:

  • The remaining portion of the query does not have to be rewritten. For instance, stats ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required