SPL
Remediation Tracking Trend - Qualys
Description
The following Splunk query will help determine remediation tracking trends within the Qualys Sourcetype:
0 0
eventtype="qualys_vm_detection_event" | stats count as eachCount |eval STATUS="Total" | table STATUS eachCount| append [|search eventtype="qualys_vm_detection_event"| stats count as eachCount by STATUS| eventstats sum(eachCount) as total | eval fixedPerc = ((eachCount/total)*100) | search STATUS=FIXED |table STATUS eachCount ]I take no credit for this. These queries were discovered on Tarun Kumar's blog.
Comments
0 total
Be the first to comment on this SPL.
Leave a comment
You must log in to post a comment.