Which of the following is true about the Splunk Common Information Model (CIM)?
To filter for only IP addresses that appear more than five times in the search results for index=games, you can use a combination of the stats and where commands. The stats command counts the occurrences of each IP address and assigns the count to IP_count. The where command then filters the results to include only those IP addresses with a count greater than five.
Here is how the complete search would look:
index=games | stats count as IP_count by IP | where IP_count > 5
Splunk Docs: stats command
Splunk Docs: where command
Splunk Answers: Filtering results using stats and where commands
Chana
4 months agoCatherin
5 months agoJesusa
5 months agoDeeann
5 months agoYan
5 months agoMelodie
5 months agoLawrence
6 months agoKip
6 months agoCathrine
6 months agoGlenn
6 months agoCristy
6 months agoStephane
6 months agoRosann
6 months agoSerita
11 months agoDick
11 months agoChristiane
11 months agoHuey
9 months agoKrissy
9 months agoNarcisa
10 months agoGeorgeanna
10 months agoOlen
11 months agoOmer
11 months agoFairy
10 months agoTayna
10 months agoRose
11 months agoAlease
12 months agoJusta
12 months agoRosalind
12 months ago