HI I am pretty new to Splunk and had a question about showing event counts from last 7 days and first time was event ever seen in a table. I use the stats to get 7 days or all time results but cannot show both the values together. I also want to display the first ever occurrence of the event in the same table index="firewall" "confidence_level=high" action=Detect|stats count by protection_name protection_name count Packet Sanity 632 Joomla Object Injection Remote Command Execution 47
... View more