Splunk Search

Tstats command

ecanmaster
Explorer

Does anybody have a good documentation regarding on how to use tstats? I have mainly used "normal" searches but need to use tstats now.
The splunk documentation I have already read and it's not good (i think you need to know already a lot before reading any splunk documentation) . With normal searches you can define the indexes source types and also the data will show , so based on the data you can refine your search, how can I do the same with tstats ?

DalJeanis
Legend

@ecanmaster - if elliot's comment has helped you with your question, then please accept the answer so that the question will show as closed. If you need more information, please let us know and we will give you more help.

0 Karma

elliotproebstel
Champion

I found this existing answer very helpful when I wanted to understand tstats:
https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...