count all events for 1 or multiple index(es)

Total count of all events for 1 or more index(es) Approach 1 (fastest)

or

does *not* support time ranges in the time picker tested on: splunk v6.6 Approach 2 (fast – especially when tsidx are *not* reduced)

supports time ranges in the time picker tested on: splunk v6.6 Approach 3 (slow – […]

Continue Reading →

Compare Successful Internal Vs External Connections

This query will display a bar chart of all successful Internal vs External SSH connections. Useful for identifying any spikes in connectivity coming from within your network remit or outside of it. Simply change the CIDR matches to match your required LANs.

   

Continue Reading →