<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to count each IP every 6 hours since its first timestamp? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-count-each-IP-every-6-hours-since-its-first-timestamp/m-p/544374#M154185</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I recieved the following question which I was not able to answer:&lt;/P&gt;&lt;P&gt;Let's simulate a system that charges each event by its IP (clientip). Each time we encounter an&lt;BR /&gt;IP it is charged by 1 cent.&lt;BR /&gt;There is however a grace period: whenever an IP is charged, for the subsequent 6 hours it will&lt;BR /&gt;not be re-charged again.&lt;BR /&gt;What will be the charge for the entire sample data? What is the query used?&lt;/P&gt;&lt;P&gt;*I used the "tutorialdata" dataset.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 17:04:50 GMT</pubDate>
    <dc:creator>stavc</dc:creator>
    <dc:date>2021-03-18T17:04:50Z</dc:date>
    <item>
      <title>How to count each IP every 6 hours since its first timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-count-each-IP-every-6-hours-since-its-first-timestamp/m-p/544374#M154185</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I recieved the following question which I was not able to answer:&lt;/P&gt;&lt;P&gt;Let's simulate a system that charges each event by its IP (clientip). Each time we encounter an&lt;BR /&gt;IP it is charged by 1 cent.&lt;BR /&gt;There is however a grace period: whenever an IP is charged, for the subsequent 6 hours it will&lt;BR /&gt;not be re-charged again.&lt;BR /&gt;What will be the charge for the entire sample data? What is the query used?&lt;/P&gt;&lt;P&gt;*I used the "tutorialdata" dataset.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 17:04:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-count-each-IP-every-6-hours-since-its-first-timestamp/m-p/544374#M154185</guid>
      <dc:creator>stavc</dc:creator>
      <dc:date>2021-03-18T17:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to count each IP every 6 hours since its first timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-count-each-IP-every-6-hours-since-its-first-timestamp/m-p/549205#M155814</link>
      <description>&lt;P&gt;Can you make some assumptions?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 23:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-count-each-IP-every-6-hours-since-its-first-timestamp/m-p/549205#M155814</guid>
      <dc:creator>MayteP</dc:creator>
      <dc:date>2021-04-23T23:57:37Z</dc:date>
    </item>
  </channel>
</rss>

