What is sseanalytics? I have seen searches with this term, but when I load them in my Splunk instance, they come back as an unknown command.
hi @belka,
Thanks for posting on Splunk Answers.
I'm glad to see that you are using the Karma bounty feature! However, it won't work if you don't engage with the user trying to answer your question. Please approve the question below so the user can receive their Karma points. Or, if the solution didn't help you, please explain why so that they — or someone else — can.
Hi @belka
It looks like @back2root answered your question thoroughly. Would you mind approving his answer, thus giving out those delicious Karma points you so gracefully offered? Thanks!
The custom search command | sseanalytics
is part of the Splunk Security Essentials App.
It returns the examples packaged with the Splunk Security Essentials App in json Format and I don't think it's very useful for any application outside of the App.
If you wan't to see the results from the search command you have, you may whant to install the Splunk Security Essentials App. How ever, browsing the App may be from more Benefit as issuing a single search using the | sseanalytics
command.