Dashboards & Visualizations

What is the first search clause?

lzhang_soliton
Path Finder

In the "UI Examples" App, the following comment can usually be found.

<!-- tells the addterm intention to put our term in the first search clause no matter what. -->

<param name="flags"><list>indexed</list></param>

In the next search command, what is the first search clause?

index=_internal source=*metrics.log | chart sum(kb) by series | sort -sum(kb) | search series=audit*
0 Karma
1 Solution

Ayn
Legend

The stuff before the first pipe, i.e. index=_internal source=*metrics.log

View solution in original post

Ayn
Legend

The stuff before the first pipe, i.e. index=_internal source=*metrics.log

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...