sistats
sistats
Synopsis
Summary indexing friendly versions of stats command.
Syntax
sistats stats_syntax
Arguments
Refer to the stats command syntax.
Description
Summary indexing friendly versions of stats command, using the same syntax. Does not require explicitly knowing what statistics are necessary to store to the summary index in order to generate a report.
Examples
Example 1: Compute the necessary information to later do 'stats avg(foo) by bar' on summary indexed results
... | sistats avg(foo) by barSee also
collect, overlap, sichart, sirare, sitop, sitimechart
Answers
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the sistats command.
This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 , 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 View the Article History for its revisions.