- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk ES Proxy Log Query Explanation Needed Regarding xswhere and "is above high"
tegosa
New Member
05-01-2015
05:41 AM
I can not find anything in the docs regarding "xswhere" and this "is above high"
Here is the query :
| tstats allow_old_summaries=true count as web_event_count from datamodel=Web by Web.src, Web.http_method | drop_dm_object_name("Web")
| xswhere web_event_count FROM count_by_http_method_by_src_1d in web by http_method is above high
Any help would be appreciated thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jcoates_splunk

Splunk Employee
05-01-2015
10:20 AM
Hi, that's coming from the Extreme Search module: http://docs.splunk.com/Documentation/ES/3.3.0/User/ExtremeSearch
