Splunk Search

Tstats events restriction / from command time range

astatrial
Contributor

Hi all,
I have a bit complicated question.

I tried to use "tstats count" command to check if there are events in a DM and because of the time range, the query took very long (a lot of events exist in the DM). I couldn't find any way to stop the tstats when the command finds even 1 event, except for head, which is not useful because it only affect when tstats is done.

So, I changed it to a from command, with head but the problem with that was to configure time range from within the query (as done with tstats "where earliest "...)

Can anyone help me find a way to stop tstats after it reach to specific count, or alternatively to use from with time range (within the query).

I am really out of ideas regarding to this...

Thanks a lot!!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...