Splunk Tips and Tricks | How to Join Two Sourcetypes Together

Поделиться
HTML-код
  • Опубликовано: 28 ноя 2024

Комментарии • 9

  • @xaviercortez5625
    @xaviercortez5625 8 месяцев назад

    I'm happy you shared this I was eager to go try join and collect at work.

    • @lamecreations_guides
      @lamecreations_guides  8 месяцев назад +1

      Let me know if you have any questions. Glad it was a help. Love that stats commanf

  • @irocz5150
    @irocz5150 7 месяцев назад

    Any good place to find commands you are using? explanation or examples.

    • @lamecreations_guides
      @lamecreations_guides  7 месяцев назад

      Which particular Commands would you like help with?
      For a lot of splunk command tutorials, this is a good play list
      ruclips.net/p/PLFF93FRoUwXGPIh4E5mBvbVxrpjGRUqIO&si=nfnefsj86JHATdX6

  • @JeffPicco
    @JeffPicco 8 месяцев назад

    Doesn't the stats command also have a limit of 50,000 by default?

    • @lamecreations_guides
      @lamecreations_guides  8 месяцев назад

      I am not aware of any limit on stats. It definitely is not 50,000.

  • @healthymealthy775
    @healthymealthy775 8 месяцев назад

    Have you ever done a token lookup using two different indexes? If so can you point me to what video that was?

    • @lamecreations_guides
      @lamecreations_guides  8 месяцев назад +1

      actually i have. Let me see if I can find the link.
      ruclips.net/video/dNTaw2VmpJ4/видео.html
      This should more or less get you to what you want. A conditional token that runs different queries based off the result.

    • @healthymealthy775
      @healthymealthy775 8 месяцев назад

      @@lamecreations_guides awesome thanks!!