Filtering pivots

Splunk Pivots can be filtered using filter elements.

Splunk supports three kinds of filter elements for use with pivots. It's important to understand each and they are explained as follows:

  • Time: Always present and cannot be removed. Time defines the time range for which your pivot will return results.
  • Match: Enables the ability to set up matching for strings, numbers, timestamps, Booleans, and IPv4 addresses (although currently only as AND, not OR, matches).
  • Limit: Enables you to restrict the number of results returned by your pivot.
Configuration options for the match and limit filter elements depend on the type of attribute that you've chosen for the element.

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.