Splunk Search

Can you skip the first x rows returned in a search?

ewanbrown
Path Finder

Hi,

If I have a query which returns 100 rows I'd like to be able to only get rows 11-100 shown (and if 200 only rows 11-200)

I have looked for an offset command similar to head or tail but I can't see one. Do you know how I could go about this?

Thanks

1 Solution

harishalipaka
Motivator

hi @ewanbrown

try like this

| makeresults 
 | fields - _time 
 | eval data="A1 A2 A3 A4 A5 A6 A7 A8 A9 A10 A11 A12 A13 A14 A15 A16 A17 A18" 
 | makemv data delim=";" 
 | mvexpand data 
 | makemv data delim=" " | mvexpand data |streamstats count as result |where result >10 |fields - result
Thanks
Harish

View solution in original post

harishalipaka
Motivator

hi @ewanbrown

just add this end of your query : |streamstats count as result |where result >10

Thanks
Harish

ewanbrown
Path Finder

Thanks! That works

0 Karma

harishalipaka
Motivator

hi @ewanbrown

try like this

| makeresults 
 | fields - _time 
 | eval data="A1 A2 A3 A4 A5 A6 A7 A8 A9 A10 A11 A12 A13 A14 A15 A16 A17 A18" 
 | makemv data delim=";" 
 | mvexpand data 
 | makemv data delim=" " | mvexpand data |streamstats count as result |where result >10 |fields - result
Thanks
Harish

adonio
Ultra Champion

nice idea @harishalipaka!

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...