<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query suggestion in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710107#M58078</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Will you describe in&amp;nbsp; more details like what exactly you are looking for .Will you just give sample data so that will help you with the query.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2025 09:46:25 GMT</pubDate>
    <dc:creator>Praz_123</dc:creator>
    <dc:date>2025-01-29T09:46:25Z</dc:date>
    <item>
      <title>Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710092#M58073</link>
      <description>&lt;P&gt;I am pretty new to Splunk. I have requirement to create dashboard panel which relates our JSESSIONIDs and severity like for specific jsessionID how many critical or error logs present.&lt;/P&gt;&lt;P&gt;Tried using stats and chart not getting desired result may be due to less idea in Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to present in pictorial way. Please suggest the Splunk query and what type of visualization will fit for this requirement?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 08:13:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710092#M58073</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-01-29T08:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710093#M58074</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;my hint is to follow the Splunk search tutorial ( &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&amp;nbsp;), so you'll be able to create your own searches.&lt;/P&gt;&lt;P&gt;then, if you like classical dashboard interface, you can use the Splunk Dashboard Examples app (&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/1603" target="_blank"&gt;https://splunkbase.splunk.com/app/1603&lt;/A&gt;&amp;nbsp;) even if it's archived, if instead you like Dashboard Studio interface, there are many examples to use, but anyway, you have to start from the Search!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 08:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710093#M58074</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-29T08:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710100#M58075</link>
      <description>&lt;P&gt;This is a very open question with many answers, but without a clearer understanding of what you want to get out of your dashboard, it is not easy to say. You could use any of the visualisations available in the dashboards, some would be more effective than other depending on the information you are trying to convey. Perhaps you should start small with a statistics table and present that to your stakeholders and ask them what else they would like to see?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 09:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710100#M58075</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-29T09:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710107#M58078</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Will you describe in&amp;nbsp; more details like what exactly you are looking for .Will you just give sample data so that will help you with the query.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 09:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710107#M58078</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2025-01-29T09:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710118#M58079</link>
      <description>&lt;H5&gt;JSESSIONID&amp;nbsp;&lt;/H5&gt;&lt;H5&gt;10002lBNXPR_Jbi4oCjxehcclRZ:1dmii9ro4&lt;/H5&gt;&lt;P&gt;&lt;SPAN&gt;100034eQfpxxxHlMxC9DQnU3jJh:1dfvt9oj5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;...... 700 count&lt;/P&gt;&lt;P&gt;Severity = Error or Critical&lt;/P&gt;&lt;P&gt;Below is the sample event:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;unit_hostname=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;GBWDC142AD011NHA.systems.uk.fed&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;support_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;5949818439961942897&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;vs_name=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/f5-tenant-01/&lt;SPAN class=""&gt;DARWIN&lt;/SPAN&gt;-GBM-UK-UAT/v-&lt;SPAN class=""&gt;darwin&lt;/SPAN&gt;-uat.systems.uk.fed-44&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;policy_name=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/Common/waf-fed-transparent&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;dest_ip=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;10.146.97.3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;dest_port=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;443&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;violations=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;protocol&lt;/SPAN&gt; &lt;SPAN class=""&gt;compliance&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;sub_violations=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;protocol&lt;/SPAN&gt; &lt;SPAN class=""&gt;compliance&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed:Body&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;GET&lt;/SPAN&gt; &lt;SPAN class=""&gt;or&lt;/SPAN&gt; &lt;SPAN class=""&gt;HEAD&lt;/SPAN&gt; &lt;SPAN class=""&gt;requests&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;violation_rating=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;attack_type=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Parser&lt;/SPAN&gt; &lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;severity=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Error&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;REQUEST&lt;/SPAN&gt; &lt;SPAN class=""&gt;BEGIN&lt;/SPAN&gt; &lt;SPAN class=""&gt;#######&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;GET&lt;/SPAN&gt; &lt;SPAN class=""&gt;/ICMClient/icm/action/actions.json&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP/1.1&lt;/SPAN&gt; &lt;SPAN class=""&gt;Host:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;rwin&lt;/SPAN&gt;-uat.systems.uk.fed&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Connection:&lt;/SPAN&gt; &lt;SPAN class=""&gt;keep-alive&lt;/SPAN&gt; &lt;SPAN class=""&gt;sec-ch-ua-platform:&lt;/SPAN&gt;&lt;SPAN&gt; ""&lt;/SPAN&gt;&lt;SPAN class=""&gt;Windows&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;X-Requested-With:&lt;/SPAN&gt; &lt;SPAN class=""&gt;XMLHttpRequest&lt;/SPAN&gt; &lt;SPAN class=""&gt;User-Agent:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Windows&lt;/SPAN&gt; &lt;SPAN class=""&gt;NT&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.0&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Win64&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;x64&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;like&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Chrome/131.0.0.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Safari/537.36&lt;/SPAN&gt; &lt;SPAN class=""&gt;Edg/131.0.0.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;sec-ch-ua:&lt;/SPAN&gt;&lt;SPAN&gt; ""&lt;/SPAN&gt;&lt;SPAN class=""&gt;Microsoft&lt;/SPAN&gt; &lt;SPAN class=""&gt;Edge&lt;/SPAN&gt;&lt;SPAN&gt;"";&lt;/SPAN&gt;&lt;SPAN class=""&gt;v=&lt;/SPAN&gt;&lt;SPAN&gt;""&lt;/SPAN&gt;&lt;SPAN class=""&gt;131&lt;/SPAN&gt;&lt;SPAN&gt;"", ""&lt;/SPAN&gt;&lt;SPAN class=""&gt;Chromium&lt;/SPAN&gt;&lt;SPAN&gt;"";&lt;/SPAN&gt;&lt;SPAN class=""&gt;v=&lt;/SPAN&gt;&lt;SPAN&gt;""&lt;/SPAN&gt;&lt;SPAN class=""&gt;131&lt;/SPAN&gt;&lt;SPAN&gt;"", ""&lt;/SPAN&gt;&lt;SPAN class=""&gt;Not_A&lt;/SPAN&gt; &lt;SPAN class=""&gt;Brand&lt;/SPAN&gt;&lt;SPAN&gt;"";&lt;/SPAN&gt;&lt;SPAN class=""&gt;v=&lt;/SPAN&gt;&lt;SPAN&gt;""&lt;/SPAN&gt;&lt;SPAN class=""&gt;24&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;DNT:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;Content-Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;application/x-www-form-urlencoded&lt;/SPAN&gt; &lt;SPAN class=""&gt;sec-ch-ua-mobile:&lt;/SPAN&gt;&lt;SPAN&gt; ?&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Accept:&lt;/SPAN&gt;&lt;SPAN&gt; *&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;* &lt;/SPAN&gt;&lt;SPAN class=""&gt;Sec-Fetch-Site:&lt;/SPAN&gt; &lt;SPAN class=""&gt;same-origin&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sec-Fetch-Mode:&lt;/SPAN&gt; &lt;SPAN class=""&gt;cors&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sec-Fetch-Dest:&lt;/SPAN&gt; &lt;SPAN class=""&gt;empty&lt;/SPAN&gt; &lt;SPAN class=""&gt;Referer:&lt;/SPAN&gt; &lt;SPAN class=""&gt;https://&lt;SPAN class=""&gt;darwin&lt;/SPAN&gt;-uat.systems.uk.fed/navigator/&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;desktop=icmUat&lt;/SPAN&gt;&lt;SPAN&gt;&amp;amp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;feature=Cases&lt;/SPAN&gt;&lt;SPAN&gt;&amp;amp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;tos=UKUAT_CMTOS2&lt;/SPAN&gt;&lt;SPAN&gt;&amp;amp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;solution=DWN&lt;/SPAN&gt; &lt;SPAN class=""&gt;Accept-Encoding:&lt;/SPAN&gt; &lt;SPAN class=""&gt;gzip&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;deflate&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;br&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;zstd&lt;/SPAN&gt; &lt;SPAN class=""&gt;Accept-Language:&lt;/SPAN&gt; &lt;SPAN class=""&gt;en-US&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;en&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class=""&gt;q=0.9&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cookie:&lt;/SPAN&gt; &lt;SPAN class=""&gt;adUsername=DNc5oBu9KkG0Z9WbdY0YMA&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;AMToken=W8s9fXK-BZFJwOfUKvHnc1QOiwE.&lt;/SPAN&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;SPAN class=""&gt;AAJTSQACMDIAAlNLABxzTGUweUUvUzRRRjZFdDl3Nk8rTlBxbkM4K2s9AAR0eXBlAANDVFMAAlMxAAIwMQ..&lt;/SPAN&gt;&lt;SPAN&gt;*; &lt;/SPAN&gt;&lt;SPAN class=""&gt;amlbcookie=01&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;LtpaToken2=tv&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;zAqV7lpFPFUr8gCWRTnBa&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;2n6YAaVE4EmZFMyoUQ3KRFFXKYEweRr0q4QwD5aZEb/x9SlmFrQghiQ7ouuQbCJ3wUJ7MTBQvc8O85Q9NQ5IzaJdXNfbSiVsTTJqsww0qprVDSERq&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;mlE28ZRDuxECH7oD/QpIZoAH5Blk0gNRIfPFOa0e11Ld9CHxwJDtNt3OyqcH0qrKW3b&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;ieB4mWh&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;u65GCOyy7EdWhRW6Cryybq/8R7Z6axHE5Gk/8q3PDBxrw/iTvZdB5UXY32wGB8DfYGR4/wc2MsbW5J4MGK8MnYJya/cLzvUJE5clEEmf3P2ef3n0m1lPXC4HartFMo7f/HA2fN0YM78kNLHx78z6EkBnOWI6kUq&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;EeC&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;Uz0RsfwoCipLRqdCrhgEofL1wQve9tIHuOrF9sRG62lfmLl67vrYBJDAaDvRE1yC&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;xLUQfcTfc0bHDxYE2Q9op/DWY6IBOpeZRi4Hmw2nd9R7HzpDB1Jy3HAJPdhEp2bATfPsD2lKYTOCpCcJKGZ3/XEMreEwm970Tz04UZSZ/8MQ86Au&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;7yVB0WXF&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;ypFYhXWCWznQfjbdWfKL5u1gxake41N0GdM95XLqydb2JxGQr/V00yqAgu6yh5BNMhhf33rx/I9RxO4jwj/2M3tGjrD0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;v5tgVkHVhBA3w7grur118FnAJ7s57A3lDtPjLFjs2w4gZ&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;JSESSIONID=0000k4OMOHFe-x8tp-F0TmQxoBN:1dmii9ro4&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;TS01492bb9=0111266d7745aebde115d8e1c57860aa8fb4d2d0645896fc5a6ed9865e53e7eed30bd3d6f3092e028ebe7f89753f63d3e54b8d8646&lt;/SPAN&gt;&lt;SPAN&gt; " &lt;/SPAN&gt;&lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;REQUEST&lt;/SPAN&gt; &lt;SPAN class=""&gt;END&lt;/SPAN&gt; &lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;RESPONSE&lt;/SPAN&gt; &lt;SPAN class=""&gt;BEGIN&lt;/SPAN&gt; &lt;SPAN class=""&gt;#######&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Response&lt;/SPAN&gt; &lt;SPAN class=""&gt;logging&lt;/SPAN&gt; &lt;SPAN class=""&gt;disabled&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTP&lt;/SPAN&gt; &lt;SPAN class=""&gt;RESPONSE&lt;/SPAN&gt; &lt;SPAN class=""&gt;END&lt;/SPAN&gt; &lt;SPAN class=""&gt;#######&lt;/SPAN&gt; &lt;SPAN class=""&gt;response_is_truncated=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;ip_client=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;10.227.31.83&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;x_forwarded_for_header_value=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;method=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;GET&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;uri=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/ICMClient/icm/action/actions.json&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;microservice=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;query_string=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;response_code=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;200&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;sig_cves=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;sig_ids=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;sig_names=&lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;} &lt;/SPAN&gt;&lt;SPAN class=""&gt;sig_set_names=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;staged_sig_cves=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;staged_sig_ids=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;staged_sig_names=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;staged_sig_set_names=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;violation_details=&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;lt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;xml&lt;/SPAN&gt; &lt;SPAN class=""&gt;version=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;1.0&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class=""&gt;encoding=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;UTF-8&lt;/SPAN&gt;&lt;SPAN&gt;'?&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;BAD_MSG&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;violation_masks&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;block&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0-0-0-0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/block&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;alarm&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;2400500004500-106200000003e-0-0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/alarm&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;learn&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0-0-0-0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/learn&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;staging&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0-0-0-0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/staging&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/violation_masks&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;request-violations&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;violation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;viol_index&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;14&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/viol_index&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;viol_name&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;VIOL_HTTP_PROTOCOL&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/viol_name&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;http_sanity_checks_status&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;64&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/http_sanity_checks_status&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;http_sub_violation_status&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;64&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/http_sub_violation_status&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;http_sub_violation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Q29udGVudC1UeXBlIGhlYWRlciBpbiBHRVQgcmVxdWVzdA==&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/http_sub_violation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/violation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/request-violations&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/BAD_MSG&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 10:44:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710118#M58079</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-01-29T10:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710120#M58080</link>
      <description>&lt;P&gt;Try something like this (assuming JSESSIONID and severity are already extracted)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| timechart dc(JSESSIONID) by severity&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 29 Jan 2025 11:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710120#M58080</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-29T11:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710121#M58081</link>
      <description>&lt;P&gt;I am expecting for a JSESSIONID(s) how many critical and error logs are there and to represent them in visualized manner..&lt;/P&gt;&lt;P&gt;Not in this way. I ran the query you given.&lt;/P&gt;&lt;P&gt;_time Critical Error&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2024-12-30&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2024-12-31&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2025-01-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 11:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710121#M58081</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-01-29T11:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710130#M58082</link>
      <description>&lt;LI-CODE lang="markup"&gt;| chart count by JSESSIONID severity&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 29 Jan 2025 12:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710130#M58082</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-29T12:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710131#M58083</link>
      <description>&lt;P&gt;ok what else fields I can visualize can you please let me know based on the event I have given.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 12:42:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710131#M58083</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2025-01-29T12:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710132#M58084</link>
      <description>&lt;P&gt;This is your data - you should understand what you are working with or find someone in your organisation who does!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 12:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710132#M58084</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-29T12:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query suggestion</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710138#M58085</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Based on your logs you can fetch data like&amp;nbsp;&lt;BR /&gt;1. For time chart -&amp;nbsp;This shows how violations are trending over time, with separate lines for successes and failures.&lt;BR /&gt;| eval violation_type=if(like(violations, "%failed%"), "Failure", "Success")&lt;BR /&gt;| timechart span=1h count by violation_type&lt;/P&gt;&lt;P&gt;2. Bar chart -&amp;nbsp;This shows the top 10 attack types by frequency.&lt;BR /&gt;| stats count by attack_type&lt;BR /&gt;| sort - count&lt;BR /&gt;| head 10&lt;/P&gt;&lt;P&gt;3. Pie or bar chart -&lt;BR /&gt;This helps you visualize how often each HTTP response code (e.g., 200, 404, 500) is returned.&lt;BR /&gt;| stats count by response_code&lt;/P&gt;&lt;P&gt;4. Bar chart -&amp;nbsp;This shows the most frequently accessed URIs, which could help you understand which endpoints are under attack.&lt;BR /&gt;| stats count by uri&lt;BR /&gt;| sort - count&lt;BR /&gt;| head 10&lt;BR /&gt;&lt;BR /&gt;Hope this works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 13:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-query-suggestion/m-p/710138#M58085</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2025-01-29T13:52:58Z</dc:date>
    </item>
  </channel>
</rss>

