What commands can be used to group events from one or more data sources?
The transaction and stats commands are two ways to group events from one or more data sources based on common fields or time ranges. The transaction command creates a single event out of a group of related events, while the stats command calculates summary statistics over a group of events. The eval and coalesce commands are used to create or combine fields, not to group events. The format command is used to format the results of a subsearch, not to group events.The top and rare commands are used to rank the most or least common values of a field, not to group events23
1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, transaction command.3: Splunk Documentation, stats command.
Limited Time Offer
25%
Off
Nakita
6 months agoRoxane
6 months agoPeter
6 months agoAzalee
6 months agoNakita
6 months agoRossana
7 months ago