Dashboards & Visualizations

What is the first search clause?

lzhang_soliton
Path Finder

In the "UI Examples" App, the following comment can usually be found.

<!-- tells the addterm intention to put our term in the first search clause no matter what. -->

<param name="flags"><list>indexed</list></param>

In the next search command, what is the first search clause?

index=_internal source=*metrics.log | chart sum(kb) by series | sort -sum(kb) | search series=audit*
0 Karma
1 Solution

Ayn
Legend

The stuff before the first pipe, i.e. index=_internal source=*metrics.log

View solution in original post

Ayn
Legend

The stuff before the first pipe, i.e. index=_internal source=*metrics.log

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

It’s go time — Boston, here we come!

Are you ready to take your Splunk skills to the next level? Get set, because Splunk University is back, and ...