So having an issue with extremesearch. I have a DD context generated for users sending emails based off their identity_id which populates fine. checked it via the xsdisplaycontext on the ID and g...
After updating to ES App version 5.3.1, the extremesearchcommands no longer exist.
An error message is shown that the command is not found.
e.g.
Search: Access - Authentication Failures By S...
Hello
Had someone ask:
ExtremeSearch Visualization (XSV), is designed as a "helper" app for Scianta Analytics' ExtremeSearch for Splunk."
Can I run extremesearchcommands and create c...
Hi,
I've noticed for a while that the SA-LDAPsearch "ldapfilter" commands can be incredibly slow in obtaining results. The process may be at 100% CPU, not generating any errors, but, just takes s...
...aving trouble with network traffic correlation rules. When digging into them I discovered how they are intertwined with the Extremesearch app using commands like xswhere to call median values of n...
...icence Volume?
If not, Will it if I write it to a lookup or store it in some other way. What are the options?
Obviously this is an extreme example, but I could use the command in a dashboard o...
The Splunk App for Enterprise Security ships with extremesearchcommands. I would like to see drastic changes in occurrences of ids signatures. ES already ships the query to populate the context: c...
...iltering uses ExtremeSearch:
| xswhere count from count_by_dest_port_1d in network_traffic by dest_port is extreme
The Content Gen search behind count_by_dest_port_1d is Port Activity By D...
I am doing a deep dive to understand the internals of a correlation search within ES so that I can justify creating new correlated searches with adjusted thresholds and/or explicit asset exceptions....