<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need simple search help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69895#M17518</link>
    <description>&lt;P&gt;index= | eval user_device=userid."_".deviceid | timechart span=1h count by user_device&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2011 20:41:09 GMT</pubDate>
    <dc:creator>fox</dc:creator>
    <dc:date>2011-03-29T20:41:09Z</dc:date>
    <item>
      <title>Need simple search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69894#M17517</link>
      <description>&lt;P&gt;Hello all,
I haven't taken as much time to understand the splunk search capabilities as I should.  I'm reading up today, however I need to get this search functional is quickly as possible.  Basically, I have data with a User and DeviceId which have many events.  I'd like to get a search that shows User with DeviceId per hour and the number of events, so something like:&lt;/P&gt;

&lt;P&gt;1pm&lt;/P&gt;

&lt;P&gt;testuser     deviceID123      200events&lt;/P&gt;

&lt;P&gt;2pm
testuser2     deviceID456   100 events&lt;/P&gt;

&lt;P&gt;I'm not sure if that'll explain it or if you need more detail.  Appreciate any help you can offer, thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 20:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69894#M17517</guid>
      <dc:creator>jayrodef</dc:creator>
      <dc:date>2011-03-29T20:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need simple search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69895#M17518</link>
      <description>&lt;P&gt;index= | eval user_device=userid."_".deviceid | timechart span=1h count by user_device&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 20:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69895#M17518</guid>
      <dc:creator>fox</dc:creator>
      <dc:date>2011-03-29T20:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need simple search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69896#M17519</link>
      <description>&lt;P&gt;index= insert your index name here&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 20:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69896#M17519</guid>
      <dc:creator>fox</dc:creator>
      <dc:date>2011-03-29T20:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Need simple search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69897#M17520</link>
      <description>&lt;P&gt;Also take a look at the Search Reference and the included cheat sheet - &lt;A href="http://www.splunk.com/base/Documentation/latest/SearchReference/SearchCheatsheet"&gt;http://www.splunk.com/base/Documentation/latest/SearchReference/SearchCheatsheet&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 20:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69897#M17520</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-03-29T20:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Need simple search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69898#M17521</link>
      <description>&lt;P&gt;Thanks so much, you guys are quick.  I'm actually reading through that link now.  Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2011 20:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-simple-search-help/m-p/69898#M17521</guid>
      <dc:creator>jayrodef</dc:creator>
      <dc:date>2011-03-29T20:53:20Z</dc:date>
    </item>
  </channel>
</rss>

