addinfo
addinfo
Synopsis
Add fields that contain common information about the current search.
Syntax
| addinfo
Description
Adds global information about the search to each event. Currently the following fields are added:
-
info_min_time: the earliest time bound for the search -
info_max_time: the latest time bound for the search -
info_sid: ID of the search that generated the event -
info_search_time: time when the search was executed.
Examples
Example 1: Add information about the search to each event.
... |addinfoSee also
Answers
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the adinfo command.
This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 , 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 , 4.3.3 , 4.3.4 , 4.3.5 , 4.3.6 , 5.0 , 5.0.1 , 5.0.2 View the Article History for its revisions.
Comments
Is there a typo above, or did something change? In 4.3.3, addinfo is returning "info_sid" not "info_search_id".
Thanks, Lalleman! Corrected.