#EventStats
💥 New SPL Dispatch drop from @thorcollective.bsky.social : eventstats 💥

Want to flag weird behavior without losing raw data? eventstats lets you compare each event to the group without rolling things up.

Read it here 👉 dispatch.thorcollective.com/p/every-even...
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
dispatch.thorcollective.com
May 13, 2025 at 9:00 PM
...sigh

Happy funny number day 🙌

ANYWAYS you guys have been COOKING this year, racking up a total of 102 days of things to do!

Show some love to Ontario's event organizers, this has been an incredible year and we're not done yet!

Source: furryeventsontario.ca#eventstats
Furry Events Ontario
Furry Events Ontario serves as a dedicated directory and collaboration hub to connect and support Ontario’s furry community.
furryeventsontario.ca
September 2, 2026 at 4:01 PM
July has overtaken June with 11 scheduled events so far! (It's only the 5th guys what the hek 😭)

Check out the stats here:
furryeventsontario.ca#eventstats
July 6, 2026 at 2:13 AM
If tstats gives you speed and eventstats gives you context...timechart gives you shape.

This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.”

dispatch.thorcollective.com/p/the-shape-...
dispatch.thorcollective.com
October 7, 2025 at 11:15 PM
Detect auth anomalies fast with tstats on accelerated Data Models. This SPL sets per-user hourly baselines, then flags events exceeding 3-sigma via eventstats—no raw data decompression. SOC-ready for Splunk 9+. Read: https://www.valtersit.com/vault/detecting-authentication-anomal
September 10, 2026 at 9:10 PM
SplunkでMCPを使う #Anthropic – Qiita

お久しぶりです。もうsplunkを退職してからはもう触ることはないかなと思っていましたが数年ぶりにSplunkを触る必要がでてきました。 いろいろ触ってたら当然のごとくSPLなんてもう覚えてないわけです。Stats...eventstats...tstatsってどう書くんだっけとかで悶々としてたので、MCPのsplunk agentを見つけたので、一旦実装してみます。 今回はこちらで作成いただいていたものがベースです。…
SplunkでMCPを使う #Anthropic – Qiita
お久しぶりです。もうsplunkを退職してからはもう触ることはないかなと思っていましたが数年ぶりにSplunkを触る必要がでてきました。 いろいろ触ってたら当然のごとくSPLなんてもう覚えてないわけです。Stats...eventstats...tstatsってどう書くんだっけとかで悶々としてたので、MCPのsplunk agentを見つけたので、一旦実装してみます。 今回はこちらで作成いただいていたものがベースです。 searchはもちろん、indexのlist、kv_storeのlistやらいろいろfunctionがあります。 環境 一旦、Localのmacにinstallしたsplunkを使います。MCPのhostはClaudeでやります。 準備 まずはlocalにgit cloneしてきます。 git clone cd splunk-mcp githubの手順だとpoetryなのですが、uvを使ってやります。splunk_mcp.pyの内部で、fastapiをcallするので、fastapi addします。 uv add "mcp" httpx fastapi splunk_mcp.pyを修正 localでやる場合、splunkが8000portでlistenしているので、fast api側のportを変更します。 vim splunk_mcp.py # FASTMCPのポートを8000から8001へ FASTMCP_PORT = int(os.environ.get("FASTMCP_PORT", "8001")) os.environ["FASTMCP_PORT"] = str(FASTMCP_PORT) 一旦起動するか確認 uv run splunk_mcp.py stdio 2025-04-10 14:46:45,501 - __main__ - INFO - 🚀 Starting Splunk MCP server in STDIO mode 起動したらCtlr+Cで抜けてください。 Claude側の設定ファイル修正 readmeだと、envファイルを置けばいけるっぽいのですがうまく読み込めていなかったので、jsonに直接書いちゃいます。 commandはuvのパス envに接続情報 argsにsplunk-mcpのパス vim ~/Library/Application\ Support/Claude/claude_desktop_config.json "splunk": { "command": "/Users/satoshi.udagawa/.local/bin/uv", "env": { "SPLUNK_HOST": "127.0.0.1", "SPLUNK_PORT": "8089", "SPLUNK_USERNAME": "admin", "SPLUNK_PASSWORD": "hogehogefugaga", "SPLUNK_SCHEME": "https", "VERIFY_SSL": "false" }, "args": [ "--directory", "/Users/satoshi.udagawa/Downloads/splunk-mcp", "run", "splunk_mcp.py", "stdio" ] } …
inmobilexion.com
April 12, 2025 at 5:49 AM
Feed: "THOR Collective Dispatch"
By: Sydney Marrone on Tuesday, May 13, 2025
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
dispatch.thorcollective.com
May 13, 2025 at 7:16 PM