An analyst is investigating the number of failed login attempts by IP address. Which SPL command can be used to create a temporary table containing the number of failed login attempts by IP address over a specific time period?
I'm leaning towards option C with the stats command. It's a classic Splunk pattern for getting counts by a field, and it should give me the results I need in a nice sorted format.
Ah, the eval command looks promising. I can use that to create a new field for the failed attempt count and then sort on that. Seems like a good approach to me.
Hmm, I'm a bit unsure about this one. The transaction command could also work, but I'm not sure if that would give me the exact count I need. I'll have to think this through carefully.
Gwen
3 months agoAdelaide
3 months agoLuis
3 months agoCecil
4 months agoLinn
4 months agoLarae
4 months agoKaran
4 months agoMeaghan
4 months agoLeota
5 months agoSanjuana
5 months agoBlossom
5 months agoIsadora
5 months agoJulio
5 months agoMarya
5 months agoTarra
1 year agoTammy
1 year agoTammara
1 year agoValda
1 year agoAnastacia
1 year agoHollis
1 year agoNieves
1 year agoEileen
1 year agoMarylin
2 years agoDelfina
1 year agoGregoria
1 year agoDana
1 year agoRobt
2 years agoAntione
2 years ago