count all events for 1 or multiple index(es)

Total count of all events for 1 or more index(es)

Approach 1 (fastest)

or
does *not* support time ranges in the time picker
tested on: splunk v6.6

Approach 2 (fast – especially when tsidx are *not* reduced)

supports time ranges in the time picker
tested on: splunk v6.6

Approach 3 (slow – if tstats is not satisfying your requirements)

supports time ranges in the time picker and ofc earliest and latest fields in the query itself
tested on: splunk v6.6

Share This:
Tagged:

Leave A Comment?