I'm currently going over our alerts, cleaning them up and optimizing them. However, I recall there being a "best practice" when it comes to writing SPL. Obviously, there may be caveats to it, bu...
See more...
I'm currently going over our alerts, cleaning them up and optimizing them. However, I recall there being a "best practice" when it comes to writing SPL. Obviously, there may be caveats to it, but what is the usual best practice when structuring your SPL commands? Is this correct or no? search, index, source, sourcetype | where, filter, regex | rex, replace, eval | stats, chart, timechart | sort, sortby | table, fields, transpose | dedup, head | eventstats, streamstats | map, lookup