Splunk Enterprise Security

Splunk ES Proxy Log Query Explanation Needed Regarding xswhere and "is above high"

tegosa
New Member

I can not find anything in the docs regarding "xswhere" and this "is above high"
Here is the query :
| tstats allow_old_summaries=true count as web_event_count from datamodel=Web by Web.src, Web.http_method | drop_dm_object_name("Web") | xswhere web_event_count FROM count_by_http_method_by_src_1d in web by http_method is above high

Any help would be appreciated thanks.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, that's coming from the Extreme Search module: http://docs.splunk.com/Documentation/ES/3.3.0/User/ExtremeSearch

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...