1: 背景:
Splunk tstats 的命令可以运行的很快,而且不占资源:
Because it searches on index-time fields instead of raw events, the tstats
command is faster than the stats
command.
By default, the tstats
command runs over accelerated and unaccelerated data models.
2: 用法:
参考: tstats - Splunk Documentation
比较有用的 参数: count
下面必须的参数:
Type of function | Supported functions and syntax | |||
---|---|---|---|---|