Dashboards & Visualizations

Can someone explain me the meaning of cluster in splunk

aditsss
Motivator

Hi Everyone,

Can some one explain me what is the meaning of these two functions:

cluster showcount=t t=0.3

cluster showcount=t t=0.9

Thanks in advance

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

with this command you could analyse events which you have in splunk and found those which are enough similar. Parameter t defines how similar those must be to taken into same cluster.

More:

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

with this command you could analyse events which you have in splunk and found those which are enough similar. Parameter t defines how similar those must be to taken into same cluster.

More:

r. Ismo

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...