Hi, splunk community.
I would like to detect regular activity with specific URL (or host) from HTTP Proxy logs.
In detail, for example, To detect specific host or URL which someone regularly request for from many many host. Regardless of how long span the regularly activity occurred.
that is, it may be occurred per an hour, or per a day, or per a month...
I tried some commands like "gentimes", "map", "trendline"..., but none of them solved my problem.
What statement should i write?
... View more