Hey there!
I have a query that will always only return one result. This result will be different depending on the input from a dashboard, but no matter the input the number of results will be either zero or one.
Is there a way to have Splunk stop querying after it finds this result? I'm searching through a lot of data so it doesn't make sense to keep searching after finding what I wanted. This is using the table command.
Use the head
command prior to the table
command:
...your search... | head 1 | table...
See http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Head for a description of the head
command.
Use the head
command prior to the table
command:
...your search... | head 1 | table...
See http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Head for a description of the head
command.
Oh wow, I was putting the head command at the end. Thanks!