Hi,
I'm after suggestions on how to best approach this problem.
I want to track over time how often I am seeing a mac address (src_mac) as categorised as:
first time: never seen before
daily: seen once per day for last 14 days
weekly: seen at least once per week for last 8 weeks
occasionally: seen before but not categorised as the above.
I then want to timechart this on a day-by-day basis.
Hi @pwild_splunk,
this is an heavy and long search, so you can have two approaches:
the first is easier (only one search) but static, the second has two parts (scheduled search and runtime search) but it's dynamic.
Ciao.
Giuseppe