I am hoping there is a place were sample queries that stored? I'm new to splunk and hope there is a repository of queries and description of what they do is avialable. My guess is most folks want to know basic data like. what are the top ten hosts by events sent, charts for what is being sent by host and other basic information that might help a person tune the amount of events coming in per day from 150 hosts. Thanks, Bill
Yes there is now!
www.gosplunk.com
The site is in its infancy but is growing with queries daily! I'm currently signed up and an active user.
Very good start.
Thanks
Not as such, but there's lots of good information in the Search Reference portion of the docs. For charting, take a look at About Reports And Charts in the User Manual.
In particular, have a look at the Search Command Cheat Sheet, which has a number of sample queries:
http://www.splunk.com/base/Documentation/4.1.5/SearchReference/SearchCheatSheet