Splunk Search

values

yin_guan
Explorer

你好,我有个问题。我需要更少的值,

  l stats count list(fileame) as filename by user

当我使用它时,心灵返回100个值。我需要快乐的值,10-20个值

Labels (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@yin_guan 

 

|stats count list(fileame) as filename by user

 

 

This will return all the filenames associated with the user. I suggest using values(). like 

这将返回与用户关联的所有文件名。我建议使用 values()。喜欢

 

|stats count values(fileame) as filename by user

 

 
if you want to limit the values add the below command with any range.

如果要限制值,请添加以下任意范围的命令。

 

 

| eval fileame=mvindex(fileame,0,9)

 

 

I hope this will help you.

我希望这能帮到您。

 

KV 

View solution in original post

kamlesh_vaghela
SplunkTrust
SplunkTrust

@yin_guan 

 

|stats count list(fileame) as filename by user

 

 

This will return all the filenames associated with the user. I suggest using values(). like 

这将返回与用户关联的所有文件名。我建议使用 values()。喜欢

 

|stats count values(fileame) as filename by user

 

 
if you want to limit the values add the below command with any range.

如果要限制值,请添加以下任意范围的命令。

 

 

| eval fileame=mvindex(fileame,0,9)

 

 

I hope this will help you.

我希望这能帮到您。

 

KV 

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...