<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tstats search that I can group over time for each of my indexes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391193#M113902</link>
    <description>&lt;P&gt;Try this: &lt;CODE&gt;| tstats count where sourcetype=* by index _time span=1d | timechart sum(count) by index&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 19:41:29 GMT</pubDate>
    <dc:creator>chrisyounger</dc:creator>
    <dc:date>2019-04-04T19:41:29Z</dc:date>
    <item>
      <title>tstats search that I can group over time for each of my indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391192#M113901</link>
      <description>&lt;P&gt;Hello ,&lt;BR /&gt;
I'm looking for assistance with an SPL search utilizing the tstats command that I can group over a specified amount of time for each of my indexes&lt;/P&gt;

&lt;P&gt;I have this command to view the entire ingestion but how can I parse it to show each index?&lt;/P&gt;

&lt;P&gt;| tstats count where sourcetype=* by _time span=1d&lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391192#M113901</guid>
      <dc:creator>bzsplunk54</dc:creator>
      <dc:date>2019-04-04T19:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: tstats search that I can group over time for each of my indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391193#M113902</link>
      <description>&lt;P&gt;Try this: &lt;CODE&gt;| tstats count where sourcetype=* by index _time span=1d | timechart sum(count) by index&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391193#M113902</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-04-04T19:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: tstats search that I can group over time for each of my indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391194#M113903</link>
      <description>&lt;P&gt;that is complete awesomeness !  thank you....&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-search-that-I-can-group-over-time-for-each-of-my-indexes/m-p/391194#M113903</guid>
      <dc:creator>bzsplunk54</dc:creator>
      <dc:date>2019-04-04T19:51:08Z</dc:date>
    </item>
  </channel>
</rss>

