An analyst is investigating the number of failed login attempts by IP address. Which SPL command can be used to create a temporary table containing the number of failed login attempts by IP address over a specific time period?
I'm leaning towards option C with the stats command. It's a classic Splunk pattern for getting counts by a field, and it should give me the results I need in a nice sorted format.
Ah, the eval command looks promising. I can use that to create a new field for the failed attempt count and then sort on that. Seems like a good approach to me.
Hmm, I'm a bit unsure about this one. The transaction command could also work, but I'm not sure if that would give me the exact count I need. I'll have to think this through carefully.
Gwen
4 months agoAdelaide
5 months agoLuis
5 months agoCecil
5 months agoLinn
5 months agoLarae
6 months agoKaran
6 months agoMeaghan
6 months agoLeota
6 months agoSanjuana
6 months agoBlossom
6 months agoIsadora
6 months agoJulio
6 months agoMarya
6 months agoTarra
2 years agoTammy
2 years agoTammara
2 years agoValda
1 year agoAnastacia
1 year agoHollis
1 year agoNieves
2 years agoEileen
2 years agoMarylin
2 years agoDelfina
2 years agoGregoria
2 years agoDana
2 years agoRobt
2 years agoAntione
2 years ago