List of questions
Related questions
Question 12 - SPLK-5001 discussion
When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?
A.
| sort by user | where count > 1000
B.
| stats count by user | where count > 1000 | sort - count
C.
| top user
D.
| stats count(user) | sort - count | where count > 1000
Your answer:
0 comments
Sorted by
Leave a comment first