Splunk Search

If I have 3 months of data, how do I write a search to return repeating values that appear in all 3 months?

thambisetty
SplunkTrust
SplunkTrust

Hi,

I have data like below:

Day month Signature
10 oct trojan
11 oct abc
12 oct efg
10 nov abc
11 nov efg
11 dec efg

I have 3 months of data and I want to check which signature is repeating for those 3 months so that my output will be "efg" since it is there for 3 months.

Please help me on this.

————————————
If this helps, give a like below.
Tags (1)
0 Karma

srinathd
Contributor

try this "stats count by signature | where count >=3"

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...