eventstats command overview - Splunk Documentation
The SPL2 eventstats command generates summary statistics from fields in your events and saves those statistics into a new field. The eventstats command places the generated statistics in new field that is added to the original raw events. SyntaxThe required syntax is in bold.eventstats[allnum=]... []How the SPL2 eventstats command worksIt's much easier to see what the SPL2 eventstats command does by showing you examples, using a set of simple events. These examples use the from command to create a set of events. Читать дальше...