TIPS & TRICKS

SplunkTalk – #46 – Multiple Values of Love

The big focus of today’s episode is on multi-value fields. Boring! Not so fast buddy!, Wilde’s got a really cool question about getting accurate counts of failed authentication in Windows 2008 Security Event Logs (ensuring machine names aren’t counted). What? Yeah! We’ll cover using “mvindex”, “coalesce”, and “mvcount” to do some really cool field manipulation for a couple of cool use cases. Action packed, fun-filled, and never lacking technical stuff, episode 46 delivers. pizzas.

Episodes are recorded live every Friday at 11AM Central Time – Email us at splunktalk@splunk.com to ask questions and have them answered on air!

Enjoy Listening!

----------------------------------------------------
Thanks!
Michael Wilde

Splunk
Posted by

Splunk

Join the Discussion