- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Beyond what's in the Search Reference and the Search Manual, are there other sites that have SPL examples available to the community?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Aside from the excellent sites from Chris above, if your goal is to learn SPL, there are a few other resources I typically recommend:
Education: Take "Advanced Searching and Reporting" from Splunk Education. Very worth your time.
Apps:
- Power of SPL - https://splunkbase.splunk.com/app/3353/
- Upleveling SPL - https://splunkbase.splunk.com/app/3020/
- Splunk SPL Examples - https://splunkbase.splunk.com/app/3456/
- Splunk Security Essentials (for examples of finding human behavior with SPL) - https://splunkbase.splunk.com/app/3435/
- Any app that strikes your fancy - look at the searches and see how they did something cool. Steal liberally 🙂
People:
- .conf is one of the best sources of wisdom out there. Archived sessions from 2013-2016 are up at conf.splunk.com. Two from the latest .conf that have great info on SPL are:
- Sign up for the Slack channel and talk to people. You soak up a lot by osmosis, and you'll meet the people who help you here on Answers.
The Splunk Book: From one of the creators of the product...http://www.splunk.com/goto/book
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @ChrisG,
in addition to the ones hinted by the other epeople I would add also Enterprise Security Content Updates (https://splunkbase.splunk.com/app/3449) that's possible to use also outside ES, eventually using the CIM data Models.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The ESCU searches are also part of Splunk Security Essentials , which you can see here
https://docs.splunksecurityessentials.com/content-detail/
and also here
https://research.splunk.com/detections/
Note that some of the searches are buggy - I've raised a few bugs in the last few days
https://github.com/splunk/security_content/issues
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi all, thank you for bringing malicious links to our attention! I have gone ahead and deleted Chris's post since the links were out of date and any another reply that had the old links. Feel free to post any updated information 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

"Archived sessions from 2013-2016 are up at conf.splunk.com" where? Can you provide the direct link please?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Here you go: https://conf.splunk.com/watch/conf-online.html?#/
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

That link only takes me to the current 2019 .conf listings.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


It does kind of look like that, because of the banner on the page. But these are in fact the 775 archived sessions recorded in previous years. If you do a search on that page, like https://conf.splunk.com/watch/conf-online.html?search=SPL#/, you will see the results are tagged with the year they were recorded.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I see now. The problem is if you go to the top left and expand Event it reflects that these are for 2016, 2017 and 2018. I am looking for the recordings before 2016.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Yes, I think that is as far back as they go, vnakra might have been mistaken.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Aside from the excellent sites from Chris above, if your goal is to learn SPL, there are a few other resources I typically recommend:
Education: Take "Advanced Searching and Reporting" from Splunk Education. Very worth your time.
Apps:
- Power of SPL - https://splunkbase.splunk.com/app/3353/
- Upleveling SPL - https://splunkbase.splunk.com/app/3020/
- Splunk SPL Examples - https://splunkbase.splunk.com/app/3456/
- Splunk Security Essentials (for examples of finding human behavior with SPL) - https://splunkbase.splunk.com/app/3435/
- Any app that strikes your fancy - look at the searches and see how they did something cool. Steal liberally 🙂
People:
- .conf is one of the best sources of wisdom out there. Archived sessions from 2013-2016 are up at conf.splunk.com. Two from the latest .conf that have great info on SPL are:
- Sign up for the Slack channel and talk to people. You soak up a lot by osmosis, and you'll meet the people who help you here on Answers.
The Splunk Book: From one of the creators of the product...http://www.splunk.com/goto/book
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Nice information … keep it up guys
