<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rare command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66560#M180442</link>
    <description>&lt;P&gt;Like kkolb said, it's the opposite of &lt;CODE&gt;top&lt;/CODE&gt; - "rare" values of fields are simply the ones that are more rare than the others. If you choose the 10 rarest field values, well then you will get the 10 values for that field that occurred the least in your result set. There's no hidden statistical algorithm or anything like that.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2013 05:58:36 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-06-25T05:58:36Z</dc:date>
    <item>
      <title>rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66554#M180436</link>
      <description>&lt;P&gt;Hi, just curious how the rare command qualifies a field as rare.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2013 03:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66554#M180436</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-06-18T03:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66555#M180437</link>
      <description>&lt;P&gt;The least common &lt;EM&gt;values&lt;/EM&gt; of a field within the timeframe. Not the rarity of the field as such.&lt;/P&gt;

&lt;P&gt;Opposite of &lt;CODE&gt;top&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2013 06:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66555#M180437</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-06-18T06:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66556#M180438</link>
      <description>&lt;P&gt;addition to /K perfect answer, you can find a description for any search command in the docs &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
see this one for rare: &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Rare"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Rare&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2013 06:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66556#M180438</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-06-18T06:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66557#M180439</link>
      <description>&lt;P&gt;Thanks /K and MuS...I was really asking about the value in a field, not the field itself, thanks for clarifying that...&lt;BR /&gt;
But let's say I'm searching user-agents being used in the environment, how does it say a result is rare?  is it the number of counts it appeared in the search?  If it is the count, is there a value/threshold/algorithm "rare" is looking into? That is what I would like to understand.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2013 00:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66557#M180439</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-06-19T00:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66558#M180440</link>
      <description>&lt;P&gt;&lt;CODE&gt;rare&lt;/CODE&gt; will look at all the values for a given field in the search results and return a list of the least common ones. There is no magic. "How does it say that a result is rare?". Because it occurs fewer times than other values. &lt;/P&gt;

&lt;P&gt;It's probably easier if you start playing with it to get a better understanding. It is not a complicated command. and it's well documented.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2013 07:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66558#M180440</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-06-20T07:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66559#M180441</link>
      <description>&lt;P&gt;/K I understood your initial answer...it is comparative to those with higher values.  My curiosity is the ratio by which it decides it is rare..is it 1:1000? 1:5000? etc...does it compare with the highest count? ave count? those are the lines of my question....&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 02:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66559#M180441</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-06-25T02:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66560#M180442</link>
      <description>&lt;P&gt;Like kkolb said, it's the opposite of &lt;CODE&gt;top&lt;/CODE&gt; - "rare" values of fields are simply the ones that are more rare than the others. If you choose the 10 rarest field values, well then you will get the 10 values for that field that occurred the least in your result set. There's no hidden statistical algorithm or anything like that.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 05:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66560#M180442</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-06-25T05:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66561#M180443</link>
      <description>&lt;P&gt;To make it clear; Let's say you search for some login events in the file &lt;CODE&gt;logins.log&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;These look like this;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;time&amp;gt; user=bob action=login&lt;BR /&gt;
&amp;lt;time&amp;gt; user=larry action=login&lt;BR /&gt;
&amp;lt;time&amp;gt; user=bob action=logout&lt;BR /&gt;
&amp;lt;time&amp;gt; user=larry action=logout&lt;BR /&gt;
&amp;lt;time&amp;gt; user=bob action=login&lt;BR /&gt;
&amp;lt;time&amp;gt; user=frank action=login&lt;BR /&gt;
&amp;lt;time&amp;gt; user=angela action=logout&lt;BR /&gt;
&amp;lt;time&amp;gt; user=larry action=logout&lt;BR /&gt;
&amp;lt;time&amp;gt; user=bob action=logout&lt;BR /&gt;
&amp;lt;time&amp;gt; user=larry action=login&lt;BR /&gt;
&amp;lt;time&amp;gt; user=angela action=logout&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;A search for &lt;CODE&gt;...| rare limit=2 user&lt;/CODE&gt; would give you;&lt;/P&gt;

&lt;P&gt;frank 1&lt;BR /&gt;
angela 2&lt;/P&gt;

&lt;P&gt;because they are the 2 least common users in the search results.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 08:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66561#M180443</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-06-25T08:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: rare command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66562#M180444</link>
      <description>&lt;P&gt;Ayn and /K, thanks for the detailed explanation.  That clarifies it.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 09:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rare-command/m-p/66562#M180444</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-06-25T09:25:02Z</dc:date>
    </item>
  </channel>
</rss>

