LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Which SPL commands should you know, and what does each one do?

stats, top/rare, timechart, eval, rex, dedup, fields, rename, sort, head/tail, transaction and lookup cover most everyday log analysis.

Command Does Example
stats Aggregates, optionally grouped … | stats count by host
top / rare Most / least frequent values … | top limit=20 url
timechart Statistic over time buckets … | timechart span=1m avg(CPU) by host
eval Computes a new field … | eval velocity=distance/time
rex Extracts fields with a regex … | rex field=_raw "From: (?<from>.*) To: (?<to>.*)"
dedup Removes duplicate results … | dedup host
fields Keeps (+) or removes (-) fields … | fields + host, ip
rename Renames a field … | rename _ip as IPAddress
sort Orders results (- = descending) … | sort ip, -url
head / tail First / last N results … | head 20
transaction Groups related events into one … | transaction host cookie maxspan=30s
lookup Adds fields from an external table … | lookup usertogroup user output group

A typical Sysmon hunt chains several of them:

index=sysmon EventCode=1 | stats count by ParentImage, Image | sort -count

That lists every parent → child process pair with its frequency. The rare pairs at the bottom are where the interesting ones hide.

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026