Splunk Search

Can you skip the first x rows returned in a search?

ewanbrown
Path Finder

Hi,

If I have a query which returns 100 rows I'd like to be able to only get rows 11-100 shown (and if 200 only rows 11-200)

I have looked for an offset command similar to head or tail but I can't see one. Do you know how I could go about this?

Thanks

1 Solution

harishalipaka
Builder

hi @ewanbrown

try like this

| makeresults 
 | fields - _time 
 | eval data="A1 A2 A3 A4 A5 A6 A7 A8 A9 A10 A11 A12 A13 A14 A15 A16 A17 A18" 
 | makemv data delim=";" 
 | mvexpand data 
 | makemv data delim=" " | mvexpand data |streamstats count as result |where result >10 |fields - result
A.Harish

View solution in original post

harishalipaka
Builder

hi @ewanbrown

just add this end of your query : |streamstats count as result |where result >10

A.Harish

ewanbrown
Path Finder

Thanks! That works

0 Karma

harishalipaka
Builder

hi @ewanbrown

try like this

| makeresults 
 | fields - _time 
 | eval data="A1 A2 A3 A4 A5 A6 A7 A8 A9 A10 A11 A12 A13 A14 A15 A16 A17 A18" 
 | makemv data delim=";" 
 | mvexpand data 
 | makemv data delim=" " | mvexpand data |streamstats count as result |where result >10 |fields - result
A.Harish

adonio
Ultra Champion

nice idea @harishalipaka!

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...