Beyond what's in the Search Reference and the Search Manual, are there other sites that have SPL examples available to the community?
Aside from the excellent sites from Chris above, if your goal is to learn SPL, there are a few other resources I typically recommend:
Education: Take "Advanced Searching and Reporting" from Splunk Education. Very worth your time.
Apps:
People:
The Splunk Book: From one of the creators of the product...http://www.splunk.com/goto/book
Hi @ChrisG,
in addition to the ones hinted by the other epeople I would add also Enterprise Security Content Updates (https://splunkbase.splunk.com/app/3449) that's possible to use also outside ES, eventually using the CIM data Models.
Ciao.
Giuseppe
The ESCU searches are also part of Splunk Security Essentials , which you can see here
https://docs.splunksecurityessentials.com/content-detail/
and also here
https://research.splunk.com/detections/
Note that some of the searches are buggy - I've raised a few bugs in the last few days
https://github.com/splunk/security_content/issues
Hi all, thank you for bringing malicious links to our attention! I have gone ahead and deleted Chris's post since the links were out of date and any another reply that had the old links. Feel free to post any updated information 🙂
"Archived sessions from 2013-2016 are up at conf.splunk.com" where? Can you provide the direct link please?
Here you go: https://conf.splunk.com/watch/conf-online.html?#/
That link only takes me to the current 2019 .conf listings.
It does kind of look like that, because of the banner on the page. But these are in fact the 775 archived sessions recorded in previous years. If you do a search on that page, like https://conf.splunk.com/watch/conf-online.html?search=SPL#/, you will see the results are tagged with the year they were recorded.
I see now. The problem is if you go to the top left and expand Event it reflects that these are for 2016, 2017 and 2018. I am looking for the recordings before 2016.
Yes, I think that is as far back as they go, vnakra might have been mistaken.
Aside from the excellent sites from Chris above, if your goal is to learn SPL, there are a few other resources I typically recommend:
Education: Take "Advanced Searching and Reporting" from Splunk Education. Very worth your time.
Apps:
People:
The Splunk Book: From one of the creators of the product...http://www.splunk.com/goto/book
Nice information … keep it up guys