First off, I want to thank you and all the other folks who have answered my slews of questions. The Splunk community is incredibly supportive!
Does the "where count > threshold" command add up the contents of the preceding minutes? Let's say the failed login count looks like the following (minsago,src_ip,count):
0,192.168.1.1,4
1,192.168.1.1,25
2,192.168.1.1,30
3,192.168.1.1,1100
4,192.168.1.1,25
5,192.168.1.1,11
If the count of events crosses the threshold at minsago=3, will that search show that at the end of minsago=4 the count of events was 1159?
... View more