Summary indexing friendly versions of rare command.
Refer to the rare command syntax.
Summary indexing friendly versions of rare command, using the same syntax. Does not require explicitly knowing what statistics are necessary to store to the summary index in order to generate a report.
Does require the rare command used to process this data have the exact same arguments as were used with the sirare command to generate the data.
Example 1: Compute the necessary information to later do 'rare foo bar' on summary indexed results.
... | sirare foo bar
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the sirare command.
This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 , 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 , 4.3.3 , 4.3.4 , 4.3.5 , 4.3.6 , 5.0 , 5.0.1 , 5.0.2