Splunk Search

Interesting fields/values , MLTK, etc

inventsekar
SplunkTrust
SplunkTrust

Hi All,

I got a bunch of logs, from which I would like get some business values. Using with or without MLTK. 

I would like to create some dashboards from these 100k log events. 

- some interesting fields, field values, etc

- the most famous, least famous patterns, etc

- some good transactions (longest/shortest, etc)

 

I read some use cases of MLTK, but, being a newbie to MLTK, i could not get something out of it. Searching on google also.

Thanks for any suggestion/printers/views, anything. 

 

Best Regards,

Sekar

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is difficult to answer without knowing more about your data.  The transaction command may be easy to use, but it usually is very slow.  Something like "| stats range(_time) as duration by session_id" may work better.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

Machine Learning is one of the industry's favorite buzzwords lately, but you don't know what to do with it then chances are you don't need it.  Your examples can be accomplished fairly easily with SPL.

Feel free to ask specific questions about your MLTK use cases, however.

---
If this reply helps you, Karma would be appreciated.

inventsekar
SplunkTrust
SplunkTrust

Thanks @richgalloway .. sure, i got your view, basic SPL is enough.
But, i thought someone may give me some suggestions, ok, let me wait for their MLTK suggestions. 

meanwhile, i would like to find out:

- some good transactions (longest/shortest, etc) - these are audit logs, which got connection established, disconnected msgs. so, pls suggest how to find the longest connection(i think by using transaction it will be easy). 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...