|
Hi Folks, Can i create summary without using sistats, sicharts etc. My search outputs a table as i don't require to use inbuilt functions like avg, first, count etc. Hence I cannot use one of these si commands. I was wondering if i can just use table field1,filed2, field3 | | addinfo | collect index=summary addtime=t marker=info_search_name=somesearchname ? Thanks, Amit |
|
Yes, you can. But it is not nearly as simple as using the si- commands. I would suggest that you also examine report acceleration in Splunk 5.x - but I don't think that will work for your case. Look here for info: Configure Summary Indexes |