<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interesting fields/values , MLTK, etc in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526864#M148716</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;.. sure, i got your view, basic SPL is enough.&lt;BR /&gt;But, i thought someone may give me some suggestions, ok, let me wait for their MLTK suggestions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;meanwhile, i would like to find out:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- some good transactions (longest/shortest, etc) - these are audit logs, which got connection established, disconnected msgs. so, pls suggest how to find the longest connection(i think by using transaction it will be easy).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 13:51:25 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2020-10-28T13:51:25Z</dc:date>
    <item>
      <title>Interesting fields/values , MLTK, etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526748#M148682</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I got a bunch of logs, from which I would like get some business values. Using with or without MLTK.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to create some dashboards from these 100k log events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- some interesting fields, field values, etc&lt;/P&gt;&lt;P&gt;- the most famous, least famous patterns, etc&lt;/P&gt;&lt;P&gt;- some good transactions (longest/shortest, etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read some use cases of MLTK, but, being a newbie to MLTK, i could not get something out of it. Searching on google also.&lt;/P&gt;&lt;P&gt;Thanks for any suggestion/printers/views, anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sekar&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 05:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526748#M148682</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-28T05:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting fields/values , MLTK, etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526859#M148715</link>
      <description>&lt;P&gt;Machine Learning is one of the industry's favorite buzzwords lately, but you don't know what to do with it then chances are you don't need it.&amp;nbsp; Your examples can be accomplished fairly easily with SPL.&lt;/P&gt;&lt;P&gt;Feel free to ask specific questions about your MLTK use cases, however.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 13:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526859#M148715</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-28T13:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting fields/values , MLTK, etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526864#M148716</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;.. sure, i got your view, basic SPL is enough.&lt;BR /&gt;But, i thought someone may give me some suggestions, ok, let me wait for their MLTK suggestions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;meanwhile, i would like to find out:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- some good transactions (longest/shortest, etc) - these are audit logs, which got connection established, disconnected msgs. so, pls suggest how to find the longest connection(i think by using transaction it will be easy).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 13:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526864#M148716</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-28T13:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting fields/values , MLTK, etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526880#M148721</link>
      <description>&lt;P&gt;This is difficult to answer without knowing more about your data.&amp;nbsp; The transaction command may be easy to use, but it usually is very slow.&amp;nbsp; Something like "&lt;FONT face="courier new,courier"&gt;| stats range(_time) as duration by session_id&lt;/FONT&gt;" may work better.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-values-MLTK-etc/m-p/526880#M148721</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-28T14:47:25Z</dc:date>
    </item>
  </channel>
</rss>

