reporting command

noun

A type of search command that, when used, orders the results into a data table. Reporting commands "transform" the specified cell values for each event into numerical values that Splunk can use for statistical purposes.

Reporting commands include chart, timechart, stats, top, rare, contingency, and highlight.

Reporting commands are required to transform search result data into the data structures required for visualizations such as column, bar, line, area, and pie charts.

Many reporting commands produce search results that the Report Builder can use to create reports and charts.

Related terms

For more information

In the User Manual:

In the Search Reference:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time