Hi,
we are testing a 8.* of Splunk version using a docker image on a POC virtual machine to migrate our 7.3.4 dev cluster.
We've noticed there is a change in values function in tstats comma...
See more...
Hi,
we are testing a 8.* of Splunk version using a docker image on a POC virtual machine to migrate our 7.3.4 dev cluster.
We've noticed there is a change in values function in tstats command:
7.3.4 version the values function can have no inputs params
8.x version the values() function must have an input param
so - for example - for a query like this:
| tstats values where index=our_index by fieldA, fieldB | rename fieldA as A, fieldB as B| where like(A,"%some_criteria%") OR like(A,"%some_criteria%") | dedup A | dedup B
we have some difficults understanding the equivalent search in a 8.x Splunk. We tried a query like this one:
| tstats values(fieldA), values(fieldB) where index=our_index by fieldA, fieldB | rename fieldA as A, fieldB as B| where like(A,"%some_criteria%") OR like(A,"%some_criteria%") | dedup A | dedup B
but we don't know if it's the right way because in the output we have two more columns:
values(A)
values(B)
with the same values of columns A and B. Do you have any suggest for this particular case or any docs in order to study these changes?
Thanks a lot.