sirare
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
sirare
Synopsis
Summary indexing friendly versions of rare command.
Syntax
sirare rare_syntax
Arguments
See syntax for the rare command.
Description
Summary indexing friendly versions of rare command, using the same syntax. Does not require explicitly knowing what statistics are necessary to store to the summary index in order to generate a report.
Examples
Example 1: Compute the necessary information to later do 'rare foo bar' on summary indexed results.
... | sirare foo barSee also
collect, overlap, sichart, sistats, sitimechart, sitop
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.