Splunk Tips and Tricks

What is this

This is where I store all my queries for threat hunting, monthly report or just daily report. Good queries is hard to find, people sell and make exculusive queries, but for me it should all be free to help young Analyst to learn all about query and stuff

Macro

You can use macro to store you complex query in Splunk

How to use tstats