Hi guys,
I am having some trouble trying to do a search. I want to do a search that involves the tools count and if but it keeps giving me an error like: Unknown search command 'count'. When I wanted to delete a few things from my index, I had to go to my access controls and turn on the delete command but when I went back I did not see anything about other command functions.
Am I doing something wrong or do I need to turn the tools on?
Please let me know!
count and if are not commands. Stats and eval are, and those use count and if.
so....
<your_search> | stats count by sourcetype
That will get you started.
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial
Sorry I did not know there was a search manual.