Hi,
we are testing a 8.* of Splunk version using a docker image on a POC virtual machine to migrate our 7.3.4 dev cluster.
We've noticed there is a change in values
function in tstats
command:
values
function can have no inputs paramsvalues()
function must have an input paramso - for example - for a query like this:
| tstats values where index=our_index by fieldA, fieldB | rename fieldA as A, fieldB as B| where like(A,"%some_criteria%") OR like(A,"%some_criteria%") | dedup A | dedup B
we have some difficults understanding the equivalent search in a 8.x Splunk. We tried a query like this one:
| tstats values(fieldA), values(fieldB) where index=our_index by fieldA, fieldB | rename fieldA as A, fieldB as B| where like(A,"%some_criteria%") OR like(A,"%some_criteria%") | dedup A | dedup B
but we don't know if it's the right way because in the output we have two more columns:
with the same values of columns A and B. Do you have any suggest for this particular case or any docs in order to study these changes?
Thanks a lot.
@to4kawa thanks. We saw the doc and probably we missed something: can you show us the point in the doc answering our question?
We don't understand how to refactor our query in order to be 8.x compatible.
Thanks
both example #9 is easy to understand.
| tstats values(fieldA) as A, values(fieldB) as B where index=our_index | where like(A,"%some_criteria%") OR like(A,"%some_criteria%")
your query is like above.