Skip to content

antipaucity

fighting the lack of good ideas

Tag: splunk

a rich man’s fieldsummary

Posted on 10 January 202310 January 2023 By antipaucity

The Splunk command fieldsummary is amazing – I use it quite frequently to explore more “new” (to me) sourcetypes, and to find out about more fields than I’ve previously used in the sourcetypes I work with most. But sometimes you want to be able to delineate more granularly than fieldsummary will allow. Maybe you have…

continue “a rich man’s fieldsummary” »

technical

remembering sqrt

Posted on 8 February 2021 By antipaucity

A couple weeks ago some folks in the splunk-usergroups.slack helped me using accum and calculating with a modulus to make a grid menu from a list. My original search had been along the lines of: | inputlookup mylookup| stats count by type| fields – count| transpose| fields – column Which was great … until my list grew…

continue “remembering sqrt” »

technical

a poor user’s guide to accelerating data models in splunk

Posted on 18 November 202018 November 2020 By antipaucity

Data Models are one of the major underpinnings of Splunk’s power and flexibility. They’re the only way to benefit from the powerful pivot command, for example. They underlie Splunk Enterprise Security (probably the biggest “non-core” use of Splunk amongst all their customers). Key to achieving peak performance from Splunk Data Models, though, is that they…

continue “a poor user’s guide to accelerating data models in splunk” »

insights, technical

splunk: match a field’s value in another field

Posted on 28 August 20205 August 2022 By antipaucity

Had a Splunk use-case present itself today on needing to determine if the value of a field was found in another – specifically, it’s about deciding if a lookup table’s category name for a network endpoint is “the same” as the dest_category assigned by a Forescout CounterACT appliance. We have “customer validated” (and we all…

continue “splunk: match a field’s value in another field” »

insights, technical

how-to timechart [possibly] better than timechart in splunk

Posted on 18 August 202019 January 2023 By antipaucity

I recently had cause to do an extensive trellised timechart for a dashboard at $CUSTOMER in Splunk. They have a couple hundred locations reporting networked devices. I needed to report on how many devices they’ve reported every day over the last 90 days (I would have liked to go back further…but retention is only 90…

continue “how-to timechart [possibly] better than timechart in splunk” »

insights, technical

finally starting to get some good docs amassed

Posted on 28 July 201825 July 2018 By antipaucity

I had a decent library of documentation, templates, hand-offs, slide decks, etc in my pre-Splunk consulting life (technically, I still have them). It’s nice to be finally getting a decent collection to draw from for my customers in my post-automation consulting life.

technical, work

you can’t disaggregate

Posted on 26 July 201824 July 2018 By antipaucity

Had a customer recently ask about to disaggregate a Splunk search that had aggregated fields because they export to CSV horribly. Here’s the thing. You can’t disaggregate aggregated fields. And there’s a Good Reasonâ„¢, too: aggregation, by definition, is a one-way street. You can’t un-average something. Average is an aggregation function. So why would you…

continue “you can’t disaggregate” »

insights, technical

Posts navigation

1 2 Next
June 2023
S M T W T F S
 123
45678910
11121314151617
18192021222324
252627282930  
« Jan    
  • Patrick Henry 23 March 1775
  • Reincarnation by Wallace McCrae (adapted by Warren Myers)
  • Famed was Beowulf
  • Fuzzy Wuzzy (anonymous)
  • One bright morning in the middle of the night (various)

Books

  • Debugging and Supporting Software Systems
  • Storage Series

External

  • Backblaze
  • Cirkul
  • Digital Ocean
  • Fundrise
  • Great Big Purple Sign
  • Password Generator
  • PayPal
  • Tech News Channel on Telegram
  • Wish List

Other Blogs

  • Abiding in Hesed
  • Chris Agocs
  • Eric Hydrick
  • Jay Loden
  • Paragraph
  • skh:tec
  • Tech News Channel on Telegram
  • Veritas Equitas

Profiles

  • LinkedIn
  • Server Fault
  • Stack Overflow
  • Super User
  • Telegram
  • Twitter

Resume

  • LinkedIn
  • Resume (PDF)

Services

  • Datente
  • IP check
  • Password Generator
  • Tech News Channel on Telegram

Support

  • Backblaze
  • Built Bar
  • Cirkul
  • Digital Ocean
  • Donations
  • Fundrise
  • PayPal
  • Robinhood
  • Wish List

Copyright © 2023 antipaucity.

Powered by PressBook Green WordPress theme