Splunk® Light (Legacy)

Search and Reporting Examples

Acrobat logo Download manual as PDF

On October 22, 2021, Splunk Light will reach its end of life. After this date, Splunk will no longer maintain or develop this product.
Acrobat logo Download topic as PDF

Calculate and chart statistics using Splunk Light


Calculate metrics for different hosts.


These searches start with a search for "error", but you can replace this search with other search terms.

1. Count the number of errors seen on each host.

error | stats count by host

2. Search for outliers. Here, outliers are hosts with a count of errors that is two standard deviations from the mean.

error | stats count by host | eventstats avg(count) as avg_count stdev(count) as std_count | where count>(2*avg_count + std_count)

Last modified on 05 April, 2016
Search for errors using Splunk Light
Compare week over week results using Splunk Light

This documentation applies to the following versions of Splunk® Light (Legacy): 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters