An analyst is investigating the number of failed login attempts by IP address. Which SPL command can be used to create a temporary table containing the number of failed login attempts by IP address over a specific time period?
I'm leaning towards option C with the stats command. It's a classic Splunk pattern for getting counts by a field, and it should give me the results I need in a nice sorted format.
Ah, the eval command looks promising. I can use that to create a new field for the failed attempt count and then sort on that. Seems like a good approach to me.
Hmm, I'm a bit unsure about this one. The transaction command could also work, but I'm not sure if that would give me the exact count I need. I'll have to think this through carefully.
Gwen
6 months agoAdelaide
6 months agoLuis
6 months agoCecil
7 months agoLinn
7 months agoLarae
7 months agoKaran
7 months agoMeaghan
7 months agoLeota
8 months agoSanjuana
8 months agoBlossom
8 months agoIsadora
8 months agoJulio
8 months agoMarya
8 months agoTarra
2 years agoTammy
2 years agoTammara
2 years agoValda
2 years agoAnastacia
2 years agoHollis
2 years agoNieves
2 years agoEileen
2 years agoMarylin
2 years agoDelfina
2 years agoGregoria
2 years agoDana
2 years agoRobt
2 years agoAntione
2 years ago