Skip to content
  • Stuff
  • Travel
  • Beverages
  • Support Antipaucity
  • Projects
  • About

antipaucity

fighting the lack of good ideas

Tag: splunk

syslog for fun (and profit?) – olf 2023 talk

Posted on 8 September 20238 September 2023 By antipaucity No Comments on syslog for fun (and profit?) – olf 2023 talk

I had the privilege of speaking at this year’s Ohio Linux Fest on the topic of syslog Slidedeck PDF – https://antipaucity.com/olf2023-syslog.pdf If you would like me to give this, or any other, talk for your organization, please contact me via LinkedIn or Twitter You can watch the talk from OLF’s live stream of the event…

continue “syslog for fun (and profit?) – olf 2023 talk” »

lug, news, personal, technical

a rich man’s fieldsummary

Posted on 10 January 202310 January 2023 By antipaucity No Comments on a rich man’s fieldsummary

The Splunk command fieldsummary is amazing – I use it quite frequently to explore more “new” (to me) sourcetypes, and to find out about more fields than I’ve previously used in the sourcetypes I work with most. But sometimes you want to be able to delineate more granularly than fieldsummary will allow. Maybe you have…

continue “a rich man’s fieldsummary” »

technical

remembering sqrt

Posted on 8 February 2021 By antipaucity No Comments on remembering sqrt

A couple weeks ago some folks in the splunk-usergroups.slack helped me using accum and calculating with a modulus to make a grid menu from a list. My original search had been along the lines of: | inputlookup mylookup| stats count by type| fields – count| transpose| fields – column Which was great … until my list grew…

continue “remembering sqrt” »

technical

a poor user’s guide to accelerating data models in splunk

Posted on 18 November 202018 November 2020 By antipaucity No Comments on a poor user’s guide to accelerating data models in splunk

Data Models are one of the major underpinnings of Splunk’s power and flexibility. They’re the only way to benefit from the powerful pivot command, for example. They underlie Splunk Enterprise Security (probably the biggest “non-core” use of Splunk amongst all their customers). Key to achieving peak performance from Splunk Data Models, though, is that they…

continue “a poor user’s guide to accelerating data models in splunk” »

insights, technical

splunk: match a field’s value in another field

Posted on 28 August 20205 August 2022 By antipaucity No Comments on splunk: match a field’s value in another field

Had a Splunk use-case present itself today on needing to determine if the value of a field was found in another – specifically, it’s about deciding if a lookup table’s category name for a network endpoint is “the same” as the dest_category assigned by a Forescout CounterACT appliance. We have “customer validated” (and we all…

continue “splunk: match a field’s value in another field” »

insights, technical

how-to timechart [possibly] better than timechart in splunk

Posted on 18 August 202019 January 2023 By antipaucity No Comments on how-to timechart [possibly] better than timechart in splunk

I recently had cause to do an extensive trellised timechart for a dashboard at $CUSTOMER in Splunk. They have a couple hundred locations reporting networked devices. I needed to report on how many devices they’ve reported every day over the last 90 days (I would have liked to go back further…but retention is only 90…

continue “how-to timechart [possibly] better than timechart in splunk” »

insights, technical

finally starting to get some good docs amassed

Posted on 28 July 201825 July 2018 By antipaucity No Comments on finally starting to get some good docs amassed

I had a decent library of documentation, templates, hand-offs, slide decks, etc in my pre-Splunk consulting life (technically, I still have them). It’s nice to be finally getting a decent collection to draw from for my customers in my post-automation consulting life.

technical, work

Posts pagination

1 2 Next
June 2025
S M T W T F S
1234567
891011121314
15161718192021
22232425262728
2930  
« Oct    
RSS Error: WP HTTP Error: cURL error 60: SSL: no alternative certificate subject name matches target hostname 'paragraph.cf'

Books

  • Debugging and Supporting Software Systems
  • Storage Series

External

  • Backblaze
  • Cirkul
  • Fundrise
  • Great Big Purple Sign
  • Password Generator
  • PayPal
  • Tech News Channel on Telegram
  • Vultr
  • Wish List

Other Blogs

  • Abiding in Hesed
  • Chris Agocs
  • Eric Hydrick
  • Jay Loden
  • Paragraph
  • skh:tec
  • Tech News Channel on Telegram
  • Veritas Equitas

Profiles

  • LinkedIn
  • Server Fault
  • Stack Overflow
  • Super User
  • Telegram
  • Twitter

Resume

  • LinkedIn
  • Resume (PDF)

Services

  • Datente
  • IP check
  • Password Generator
  • Tech News Channel on Telegram

Support

  • Backblaze
  • Built Bar
  • Cirkul
  • Donations
  • Fundrise
  • PayPal
  • Robinhood
  • Vultr
  • Wish List

35-questions 48laws adoption automation blog blogging books business career centos cloud community documentation email encryption facebook google history how-to hpsa ifttt linux money networking politics prediction proxy review scifi security social social-media splunk ssl startup storage sun-tzu tutorial twitter virtualization vmware wordpress work writing zombie

Copyright © 2025 antipaucity.

Powered by PressBook Green WordPress theme