Hi Folks,
Can i create summary without using sistats, sicharts etc. My search outputs a table as i don't require to use inbuilt functions like avg, first, count etc. Hence I cannot use one of these si commands. I was wondering if i can just use table field1,filed2, field3 | | addinfo | collect index=summary addtime=t marker=info_search_name=somesearchname ?
Thanks,
Amit
Yes, you can. But it is not nearly as simple as using the si- commands. I would suggest that you also examine report acceleration in Splunk 5.x - but I don't think that will work for your case.
Look here for info: Configure Summary Indexes