Splunk Search

How to count each IP every 6 hours since its first timestamp?

New Member


I recieved the following question which I was not able to answer:

Let's simulate a system that charges each event by its IP (clientip). Each time we encounter an
IP it is charged by 1 cent.
There is however a grace period: whenever an IP is charged, for the subsequent 6 hours it will
not be re-charged again.
What will be the charge for the entire sample data? What is the query used?

*I used the "tutorialdata" dataset.


Labels (1)
0 Karma

New Member

Can you make some assumptions?

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.