Splunk Search

Need simple search help

jayrodef
Explorer

Hello all, I haven't taken as much time to understand the splunk search capabilities as I should. I'm reading up today, however I need to get this search functional is quickly as possible. Basically, I have data with a User and DeviceId which have many events. I'd like to get a search that shows User with DeviceId per hour and the number of events, so something like:

1pm

testuser deviceID123 200events

2pm testuser2 deviceID456 100 events

I'm not sure if that'll explain it or if you need more detail. Appreciate any help you can offer, thanks.

Tags (1)
1 Solution

fox
Path Finder

index= | eval user_device=userid."_".deviceid | timechart span=1h count by user_device

View solution in original post

fox
Path Finder

index= | eval user_device=userid."_".deviceid | timechart span=1h count by user_device

jayrodef
Explorer

Thanks so much, you guys are quick. I'm actually reading through that link now. Thanks again.

0 Karma

southeringtonp
Motivator

Also take a look at the Search Reference and the included cheat sheet - http://www.splunk.com/base/Documentation/latest/SearchReference/SearchCheatsheet

fox
Path Finder

index= insert your index name here

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...