<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search web traffic from a particular ip address, count hostnames by 15 minute incriments | then chart count by catdesc. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132768#M27284</link>
    <description>&lt;P&gt;I might do something like this. I don't know if it's the most efficient or whatever but hope this helps. I like to use list rather than values but I guess I'm the only one. Maybe look at the values command as well.&lt;/P&gt;

&lt;P&gt;ipaddress &lt;A href="http://www.*(I'm"&gt;www.*(I'm&lt;/A&gt; guessing this is a source or sourcetype?) | bucket span=15m _time | stats list(catdesc) AS Description, list(count) as Count by (ipaddress/hostname) | sort -Count &lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2014 19:44:33 GMT</pubDate>
    <dc:creator>ryangibson99</dc:creator>
    <dc:date>2014-09-19T19:44:33Z</dc:date>
    <item>
      <title>How to search web traffic from a particular ip address, count hostnames by 15 minute incriments | then chart count by catdesc.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132767#M27283</link>
      <description>&lt;P&gt;What I am trying to get:&lt;BR /&gt;
A 14 days chart of category descriptions that has a meaningful count.  Right now I see things like:&lt;/P&gt;

&lt;P&gt;Type____________________________________________________________Count&lt;BR /&gt;
Search Engines and Portal   7000&lt;/P&gt;

&lt;P&gt;What I would like it be"&lt;BR /&gt;
Type_______________________________________________________________Count&lt;BR /&gt;
Search Engines and Portal   344&lt;/P&gt;

&lt;P&gt;On the back end a person went to google and did multiple searches for ~ 15 minutes a day over 14 days. &lt;/P&gt;

&lt;P&gt;Detailed thoughts:&lt;BR /&gt;
Look at a ip address's website traffic over 14 days, distinguish visit to a site vice numerous log entries due to initial visit to a site (walmart.com pulls something like 6-9 different events).  Transform that into catdesc to show # of visits to a particular type over 14 days.&lt;/P&gt;

&lt;P&gt;What I had originally tried was:&lt;BR /&gt;
(IP address) &lt;A href="http://www.*%7C"&gt;www.*|&lt;/A&gt; chart count by catdesc limit=0 | sort -count&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 16:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132767#M27283</guid>
      <dc:creator>DW2054</dc:creator>
      <dc:date>2014-09-19T16:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to search web traffic from a particular ip address, count hostnames by 15 minute incriments | then chart count by catdesc.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132768#M27284</link>
      <description>&lt;P&gt;I might do something like this. I don't know if it's the most efficient or whatever but hope this helps. I like to use list rather than values but I guess I'm the only one. Maybe look at the values command as well.&lt;/P&gt;

&lt;P&gt;ipaddress &lt;A href="http://www.*(I'm"&gt;www.*(I'm&lt;/A&gt; guessing this is a source or sourcetype?) | bucket span=15m _time | stats list(catdesc) AS Description, list(count) as Count by (ipaddress/hostname) | sort -Count &lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132768#M27284</guid>
      <dc:creator>ryangibson99</dc:creator>
      <dc:date>2014-09-19T19:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to search web traffic from a particular ip address, count hostnames by 15 minute incriments | then chart count by catdesc.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132769#M27285</link>
      <description>&lt;P&gt;Ryan,&lt;/P&gt;

&lt;P&gt;Thank you for the answer, I really appreciate it.&lt;/P&gt;

&lt;P&gt;This is what I used: (time 24 hours)&lt;BR /&gt;
(IP Adress) &lt;A href="http://www.*%7C"&gt;www.*|&lt;/A&gt; bucket span=15m _time | stats list(catdesc) AS Description, list(count) as count by hostname | sort -Count&lt;/P&gt;

&lt;P&gt;I get:&lt;BR /&gt;
Hostname Description Count&lt;BR /&gt;
Google       Search Engines and Portals  was blank.&lt;/P&gt;

&lt;P&gt;Do you know how to covert the descriptions to counts and only show:&lt;/P&gt;

&lt;P&gt;Google Search Engines and Portals                  37.&lt;/P&gt;

&lt;P&gt;Does the bucket span 15 take the length (24 hours) and break it down into 15 minute increments?&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 22:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-search-web-traffic-from-a-particular-ip-address-count/m-p/132769#M27285</guid>
      <dc:creator>DW2054</dc:creator>
      <dc:date>2014-09-19T22:37:52Z</dc:date>
    </item>
  </channel>
</rss>

