<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Gabriel Vasseur]]></title><description><![CDATA[Gabriel Vasseur]]></description><link>https://www.gabrielvasseur.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Tue, 03 Mar 2026 20:15:08 GMT</lastBuildDate><atom:link href="https://www.gabrielvasseur.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Advent of code in SPL - 2025 day 8]]></title><description><![CDATA[Day 8 is here . Part 1 So the first challenge is to enumerate all possible pairs. Let's play with very simple data to start with: I guess eventstats is a good way to bring all of the events into each of the events: Now we just have to mvexpand item2. But there are a couple of problems: we can't have pairs made of twice the same event, that's not possible. the order doesn't matter in pairs, so we need to dedup them somehow. Cool, so now we know how to enumerate pairs. Let's apply it to the...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-8</link><guid isPermaLink="false">69a736ccb220091e29d88db3</guid><category><![CDATA[Advent]]></category><category><![CDATA[News]]></category><pubDate>Tue, 03 Mar 2026 19:41:09 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_2804f54da59b4840bf92e9ccd61ca47c~mv2.png/v1/fit/w_627,h_302,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 7]]></title><description><![CDATA[Day 7 is here . Part 1 - visual solution One thing I've learned about myself with these challenges, is that I always want to make the solution as splunky as possible. For me that means starting with a stream of events, i.e. treating the challenge data as one event per line, and pretending they are indexed events in splunk. That's also why I wanted to use timed lookups in day 5. Of course, that kind of approach is not always ideal for this type of programming challenges, and it pays to think...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-7</link><guid isPermaLink="false">69a1d2429d34acb7c434b013</guid><category><![CDATA[Advent]]></category><pubDate>Fri, 27 Feb 2026 17:40:18 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_bbfe780c88874c84864d40efd51d0f97~mv2.png/v1/fit/w_514,h_316,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 6]]></title><description><![CDATA[Day 6 is here . As always we save the challenge data as a csv file, add a column header (just one column called "math"), and upload it to splunk: Part 1 Cephalopod math is organised in columns, which is going against of the grain in splunk. So a good first step would be to transpose it. Before we can do that, we need to give a name to each field: Then we can use the transpose command: Then we need to split each field on spaces: Note: sadly split does not take a regular expression for the...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-6</link><guid isPermaLink="false">699899caf63bd550f09f6983</guid><category><![CDATA[Advent]]></category><pubDate>Fri, 20 Feb 2026 17:34:55 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_a567a9fae90a406e881b0d89c1e640c3~mv2.png/v1/fit/w_693,h_196,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - Day 5]]></title><description><![CDATA[Note: I brought up these challenges to the puzzle channel on the Splunk Community slack a few weeks ago, and I'm delighted to see that ITWhisperer  has now started his own series about it! His day 1 is here . I encourage you to check out his solutions as it's great to see different ways of thinking! Day 5 is here . For this one, my thoughts went to lookups. The idea would be to create a lookup of fresh ingredients. Then for each ingredient all we have to do is check if it's in the lookup. I...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-day-5</link><guid isPermaLink="false">698a5af7e24b711372bf469c</guid><category><![CDATA[Advent]]></category><pubDate>Tue, 10 Feb 2026 17:35:04 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_a73956dff68c417c84ebe2ad9a53392c~mv2.png/v1/fit/w_592,h_141,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 4]]></title><description><![CDATA[Day 4 is here . Part 1 Let's start with the example data: For each position, we need to count the number of neighbours. That's ok for left and right neighbours, but for the ones above and below, we need the previous and next row. That means using streamstats with current=f! But we need to use it twice now: It kind of works, but you can see we have two problems: we have a useless record at the top. We can simply add | search row=* we're missing one at the bottom. All we need for that is to add...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-4</link><guid isPermaLink="false">6981f4e5f1c6744fd01932bc</guid><category><![CDATA[Advent]]></category><pubDate>Wed, 04 Feb 2026 17:37:57 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_297ed84f8c3543a08b22cb471cd76ae2~mv2.png/v1/fit/w_358,h_361,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 3]]></title><description><![CDATA[Day 3 is here . Part 1   This one isn't too difficult. Given a series of digits such as 818181911112111, we need to pick two digits (conserving the order) to make the highest 2-digit number possible, so in this example 92. The first digit is obviously the most important, so we always want the highest one available, but we need to reserve at least one digit at the end of the bank for the second digit.   So take the bank, remove the last digit, and find the highest digit: Now for the second...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-3</link><guid isPermaLink="false">697903ec66503bc679d15fdf</guid><category><![CDATA[Advent]]></category><pubDate>Tue, 27 Jan 2026 21:13:43 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_c4bbf38c93a94f99b0ffb37309baee85~mv2.png/v1/fit/w_664,h_81,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 2]]></title><description><![CDATA[(Edited to use mvrange) Day 2 of the 2025 advent of code challenges is here: https://adventofcode.com/2025/day/2  You won't be able to do it if you haven't done day 1 first . We can break down this challenge in several steps: given a range (e.g. 11-22), enumerate all the IDs within the range (e.g. 11,12,13,...,22) given a number, assess whether it's made of 2 repeated halves somehow do this for all the ranges all together to get the solution Step 1 For this challenge, we'll start small. Let's...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-2</link><guid isPermaLink="false">696e5f59e4340f7772ba336c</guid><category><![CDATA[Advent]]></category><pubDate>Mon, 19 Jan 2026 17:31:19 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_ba10abc93c7a411ead08b09bd0bdf955~mv2.png/v1/fit/w_488,h_79,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Advent of code in SPL - 2025 day 1]]></title><description><![CDATA[Advent of code  is a series of Christmas-themed programming challenges that's been running for more than 10 years now. While SPL is not exactly a fully-fledged programming language, I had heard in the past of at least one person (thank you Paul Dean for the idea!) attempting to do the challenges in SPL and this year I thought I would give it a go. I know it's more than a month too late, but this is the first of a series of articles tackling 2025's challenges in SPL. We won't manage all of...]]></description><link>https://www.gabrielvasseur.com/post/advent-of-code-in-spl-2025-day-1</link><guid isPermaLink="false">69650fa8f1ba376a5bbc436d</guid><category><![CDATA[Advent]]></category><pubDate>Mon, 12 Jan 2026 17:31:32 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_f39b69e864624535a8cf9c2258ee5214~mv2.png/v1/fit/w_195,h_237,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Shrink your windows event logs license costs with ingest actions!]]></title><description><![CDATA[Windows events are a large part of the volume of logs ingested in a lot of splunk deployments. Wouldn't be cool if we could shrink them so they don't eat up so much precious precious license? In this post I'll walk through how I rebuilt Windows Event Logs (WELs) into a compact, Splunk-friendly format, cuting size by up to 60% without breaking field extractions. Key takeaways With a few targeted ingest actions and props/transforms tweaks, you can shrink Windows logs dramatically, without...]]></description><link>https://www.gabrielvasseur.com/post/shrink-your-windows-event-logs-license-costs-with-ingest-actions</link><guid isPermaLink="false">68f88b732f6e63dae8b9195f</guid><category><![CDATA[News]]></category><category><![CDATA[Articles]]></category><pubDate>Mon, 27 Oct 2025 09:41:21 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_1a405f4d76344d6e90a2c08b0017d9dd~mv2.png/v1/fit/w_918,h_411,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[ES8 findings, intermediate findings, etc confusion!]]></title><description><![CDATA[The key thing I did not appreciate when I wrote the previous version of this post is that the Risk data model is now fed from...]]></description><link>https://www.gabrielvasseur.com/post/es8-findings-intermediate-findings-etc-confusion</link><guid isPermaLink="false">68babf4298886589b9fdc1f2</guid><category><![CDATA[News]]></category><category><![CDATA[Articles]]></category><pubDate>Fri, 05 Sep 2025 11:01:07 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_e0baf4448cf345ceb8e9c3c961365522~mv2.png/v1/fit/w_1000,h_138,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[RBA: Aggregate user &#38; system risks!]]></title><description><![CDATA[Since RBA is all about aggregating security events that are related to the same entity, Assets &#38; Identities normalisation is crucial to...]]></description><link>https://www.gabrielvasseur.com/post/rba-aggregate-user-system-risks</link><guid isPermaLink="false">67580569bbb6afa37963aa9d</guid><category><![CDATA[News]]></category><category><![CDATA[Articles]]></category><category><![CDATA[RBA]]></category><pubDate>Mon, 06 Jan 2025 11:27:33 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_fbe48f6852a34750821eefe965bbcb00~mv2.jpg/v1/fit/w_816,h_284,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Untable, xyseries, transpose clarified!]]></title><description><![CDATA[These 3 table-manipulating commands are occasionally very useful but they are also quite confusing. For years, I've relied on the...]]></description><link>https://www.gabrielvasseur.com/post/untable-xyseries-transpose-clarified</link><guid isPermaLink="false">674d9467cf5a084071696fea</guid><category><![CDATA[Articles]]></category><pubDate>Mon, 02 Dec 2024 11:07:50 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_841874ccbd674c7296a0c1c576f6bd50~mv2.jpg/v1/fit/w_1000,h_978,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Use Ingest Actions to shrink your ingest and make the most of your license!]]></title><description><![CDATA[On the 18th of September 2024 I gave a talk on this topic at the London Splunk User Group meetup. Ingest Actions are a simple feature of...]]></description><link>https://www.gabrielvasseur.com/post/use-ingest-actions-to-shrink-your-ingest-and-make-the-most-of-your-license</link><guid isPermaLink="false">66ed886483ff094bbf570739</guid><category><![CDATA[Talks]]></category><category><![CDATA[News]]></category><pubDate>Fri, 20 Sep 2024 14:39:52 GMT</pubDate><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA["And the nominees are..." - Wish me luck!]]></title><description><![CDATA[I have been nominated for a 2023 Splunkie Award and I am delighted to be a finalist for the Inventor Award! https://conf.splunk.com/the-s...]]></description><link>https://www.gabrielvasseur.com/post/and-the-nominees-are-wish-me-luck</link><guid isPermaLink="false">66d44c282077f1cfef806fe3</guid><category><![CDATA[News]]></category><pubDate>Mon, 03 Jul 2023 08:05:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_16f546855eae4a1b876fdab32dc9b440~mv2.png/v1/fit/w_377,h_421,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[RBA: a better way to dedup risk events]]></title><description><![CDATA[In this post we’re discussing an advanced way to dedup risk events in your risk alerts (RIRs) and at the same time have the RIR results...]]></description><link>https://www.gabrielvasseur.com/post/rba-a-better-way-to-dedup-risk-events</link><guid isPermaLink="false">66d44c282077f1cfef806fe4</guid><category><![CDATA[RBA]]></category><category><![CDATA[Articles]]></category><pubDate>Mon, 22 May 2023 12:14:27 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_6f11a071fe7d4b49855fd1c7aee9e07f~mv2.png/v1/fit/w_1000,h_603,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Site Map]]></title><description><![CDATA[Use this page as a quick way to find which areas of this website have value for you. My apps ES Choreographer : manage ES correlation...]]></description><link>https://www.gabrielvasseur.com/post/site-map</link><guid isPermaLink="false">66d44c282077f1cfef806fd6</guid><pubDate>Tue, 16 May 2023 14:29:00 GMT</pubDate><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Conf Manager]]></title><description><![CDATA[This is the documentation for the Conf Manager  app on splunkbase. This app allows you to search your knowledge objects and track their...]]></description><link>https://www.gabrielvasseur.com/post/conf-manager</link><guid isPermaLink="false">66d44c282077f1cfef806fe7</guid><category><![CDATA[Apps]]></category><pubDate>Tue, 16 May 2023 13:05:46 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_4857b23648d54a60a142184c88015517~mv2.png/v1/fit/w_1000,h_849,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Linux tips]]></title><description><![CDATA[This for the most part isn't splunk-specific, but if you do any amount of administration on the linux command line, you might find it...]]></description><link>https://www.gabrielvasseur.com/post/linux-tips</link><guid isPermaLink="false">66d44c282077f1cfef806fdd</guid><category><![CDATA[Articles]]></category><pubDate>Sat, 30 Apr 2022 11:30:13 GMT</pubDate><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[Splunk workload optimisation]]></title><description><![CDATA[Assess your search workload with this simple dashboard. Here's a very quick dashboard to identify what uses your splunk platform...]]></description><link>https://www.gabrielvasseur.com/post/splunk-workload-optimisation</link><guid isPermaLink="false">66d44c282077f1cfef806fd2</guid><category><![CDATA[Articles]]></category><pubDate>Tue, 26 Apr 2022 13:52:34 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_f9e96775534447d598309293fd124f2b~mv2.png/v1/fit/w_942,h_364,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item><item><title><![CDATA[ES-Choreographer]]></title><description><![CDATA[This is the documentation for the ES-Choreographer  app on splunkbase. This app offers various frameworks to help manage and improve...]]></description><link>https://www.gabrielvasseur.com/post/es-choreographer</link><guid isPermaLink="false">66d44c282077f1cfef806fe5</guid><category><![CDATA[Apps]]></category><pubDate>Mon, 28 Feb 2022 14:24:59 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/13f3dd_20c0b34db7da43e3b9bc539c587f2c15~mv2.png/v1/fit/w_1000,h_517,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gabriel Vasseur</dc:creator></item></channel></rss>