...eeps eventorder intact. But stats values() sorts the values using lexicographical order.
Is there any other functions or ways that keeps the eventorder intact like stats list()?
...loses a transaction
* "field1" and "field2" have relatively close timestamps (5 minutes at most between them)
I've tried many combinations of "transaction", "filldown" and "sort" functions, but I'm u...
...simple fix by editing one of the python functions in the app so that Splunk indexes the latest event, but I haven't quite figured out a fix. Has anyone else experienced this issue or know of a workaround?
...ata 1 A 2 1 B 3 3 B Data 3 B Data 3 B 4 3 Is this possible? I looked into mapping functions (to try and map the first eventResult to the eventName) but couldn't f...
...rite a search query to identify the functions that run for more than 'x' seconds, using transaction command as follows (i.e. extract the 'function' and use thread_name and function as unique IDs)
s...
Hello, I have some issues extracting fields from the following raw event. I should be getting following fileds from this event. Any help will be highly appreciated. Thank you! Field Names: T...
When I search with stats first(myfield) last(myfield)
They return the opposite !!!!
example :
10/10/2010 myfield=A
12/12/2012 myfield=B
| stats first(myfield) last(myfield)
returns fir...
...an't write custom functions with python that works with the fast mode ? Did I forget something in the command.conf file or somewhere else ? Or maybe is there a way to force the smart mode to fetch the f...
...itle="Human" name="Rag\'n\'Bone Man" score="763,862"
title="Closer" name="Chainsmokers" score="8,980,580"...etc
I am messing around with modulus and mv functions in order to first connect the 3...