Hello all, I haven't taken as much time to understand the splunk search capabilities as I should. I'm reading up today, however I need to get this search functional is quickly as possible. Basically, I have data with a User and DeviceId which have many events. I'd like to get a search that shows User with DeviceId per hour and the number of events, so something like:
testuser deviceID123 200events
2pm testuser2 deviceID456 100 events
I'm not sure if that'll explain it or if you need more detail. Appreciate any help you can offer, thanks.