Splunk Enterprise Security

Splunk ES Proxy Log Query Explanation Needed Regarding xswhere and "is above high"

tegosa
New Member

I can not find anything in the docs regarding "xswhere" and this "is above high"
Here is the query :
| tstats allow_old_summaries=true count as web_event_count from datamodel=Web by Web.src, Web.http_method | drop_dm_object_name("Web") | xswhere web_event_count FROM count_by_http_method_by_src_1d in web by http_method is above high

Any help would be appreciated thanks.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, that's coming from the Extreme Search module: http://docs.splunk.com/Documentation/ES/3.3.0/User/ExtremeSearch

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...