Splunk Search

How to find the event count that are not repeated and repeated events in next consecutive quarter over year ?

venkatesh0464
Engager

I used set diff command, it works fine for less rows. But for my search it terminating and limiting the search results. Is there any other ways to do this. Also is there any possibility for parsing the splunk results with Python and plotting the bar graph graph in splunk visualization?

Tags (1)
0 Karma

valiquet
Contributor

| stats count by event

0 Karma

venkatesh0464
Engager

Similar One:
https://www.splunk.com/blog/2016/02/29/monitoring-vulnerability-deltas.html

Here data comparison over quarter. one series value in Q1 is Q1+Q2,Q4-Q2,Q1

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...