<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: List field values as input without rendering the events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108814#M28364</link>
    <description>&lt;P&gt;Well this IS rendering events,,,,fyi if you have 300.000 events per minute then this is slow for shooting it in the pulldown module...&lt;BR /&gt;
I am testing now with | metadata type=hosts and subsearch for the sourcetype...( and index)&lt;BR /&gt;
But no luck,,,i think i have to schedule it with summary indexing,,,&lt;/P&gt;</description>
    <pubDate>Sat, 12 Nov 2011 18:50:46 GMT</pubDate>
    <dc:creator>Starlette</dc:creator>
    <dc:date>2011-11-12T18:50:46Z</dc:date>
    <item>
      <title>List field values as input without rendering the events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108812#M28362</link>
      <description>&lt;P&gt;Is there a smart way to list field values as input without rendering the events?&lt;BR /&gt;
Example :&lt;/P&gt;

&lt;P&gt;I want to list the hosts for a sourcetype=named&lt;BR /&gt;
so instead of doing a  &lt;/P&gt;

&lt;P&gt;sourcetype=named | fields host  ( and have to use a earliest time)&lt;BR /&gt;
cause this takes time to render the pulldown module....maybee |metadata ?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2011 16:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108812#M28362</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2011-11-12T16:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: List field values as input without rendering the events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108813#M28363</link>
      <description>&lt;P&gt;Not sure I fully understand your question but perhaps this can give you what you need:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;sourcetype=named | stats count by host&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;gt; please upvote and accept answer if you find it useful - thanks!&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2011 17:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108813#M28363</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2011-11-12T17:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: List field values as input without rendering the events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108814#M28364</link>
      <description>&lt;P&gt;Well this IS rendering events,,,,fyi if you have 300.000 events per minute then this is slow for shooting it in the pulldown module...&lt;BR /&gt;
I am testing now with | metadata type=hosts and subsearch for the sourcetype...( and index)&lt;BR /&gt;
But no luck,,,i think i have to schedule it with summary indexing,,,&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2011 18:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108814#M28364</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2011-11-12T18:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: List field values as input without rendering the events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108815#M28365</link>
      <description>&lt;P&gt;Yep, if you have that many events per minute and you want to know sourcetypes by hosts over a long period summary indexing is probably your best bet. I found this answer that sheds some more light on the same topic: &lt;A href="http://splunk-base.splunk.com/answers/10005/how-to-get-host-sourcetype-and-source-from-a-single-metadata-search"&gt;http://splunk-base.splunk.com/answers/10005/how-to-get-host-sourcetype-and-source-from-a-single-metadata-search&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;gt; please upvote and accept answer if you find it useful - thanks!&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2011 19:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/List-field-values-as-input-without-rendering-the-events/m-p/108815#M28365</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2011-11-12T19:39:30Z</dc:date>
    </item>
  </channel>
</rss>

