Splunk Search

Tstats command

ecanmaster
Explorer

Does anybody have a good documentation regarding on how to use tstats? I have mainly used "normal" searches but need to use tstats now.
The splunk documentation I have already read and it's not good (i think you need to know already a lot before reading any splunk documentation) . With normal searches you can define the indexes source types and also the data will show , so based on the data you can refine your search, how can I do the same with tstats ?

DalJeanis
Legend

@ecanmaster - if elliot's comment has helped you with your question, then please accept the answer so that the question will show as closed. If you need more information, please let us know and we will give you more help.

0 Karma

elliotproebstel
Champion

I found this existing answer very helpful when I wanted to understand tstats:
https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...