Splunk Search

Time Stamp

New Member

May seem trivial but it is alluding me! What would I add in the search to extract the time of the event?

host=server sourcetype=iis NOT #Software NOT #Fields NOT /favicon.ico (method=GET OR method=POST) NOT eventtype="web-imagefile" | stats count by src_ip,user,uri_stem


Tags (1)
0 Karma


What do you want to do with _time?

0 Karma

Super Champion

stats count by src_ip,user,uri_stem,_time

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...