SPLUNK 笔记

Required and optional arguments

  1. <> 必选参数
  2. []可选参数
  1. 数据类型

Data types

The nomenclature used for the data types in SPL syntax are described in the following table.

SyntaxData typeNotes
<bool>booleanUse true or false. Other variations are accepted. For example, for true you can also use 't', 'T', 'TRUE', 'yes', or the number one ( 1 ). For false you can also specify 'no', the number zero ( 0 ), and variations of the word false, similar to the variations of the word true.
<field>A field name. You cannot specify a wild card for the field name.See <wc-field>.
<int> or <integer>An integer that can be a positive or negative value.Sometimes referred to as a "signed" integer. See <unsigned int>.
<string>stringSee <wc-string>.
<unsigned int>unsigned integerAn unsigned integer must be positive value. Unsigned integers can be larger numbers than signed integers.
<wc-field>A field name or a partial name with a wildcard character to specify multiple, similarly named fields.Use the asterisk ( * ) character as the wildcard character.
<wc-string>A string value or partial string value with a wildcard character.Use the asterisk ( * ) character as the wildcard character.

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值