Splunk Search

Count logging systems


Is there a fast way to count all logging systems to a certain index?
Currently I use the "stats" command with the "distinct_count" and it is very slow on that index.

index=windows | stats distinct_count(system)
0 Karma

Revered Legend

The field system is a field in log?

0 Karma


Narrowing your search time window will help. See if this is any faster:

index=windows | dedup system | stats count(system)
If this reply helps you, an upvote would be appreciated.
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!