Splunk Search

Time Stamp

wrays
New Member

May seem trivial but it is alluding me! What would I add in the search to extract the time of the event?

host=server sourcetype=iis NOT #Software NOT #Fields NOT /favicon.ico (method=GET OR method=POST) NOT eventtype="web-imagefile" | stats count by src_ip,user,uri_stem

Thanks!

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

What do you want to do with _time?

0 Karma

lukejadamec
Super Champion

Try
stats count by src_ip,user,uri_stem,_time

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...