<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to generate one notable for multiple events? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-generate-one-notable-for-multiple-events/m-p/636167#M15838</link>
    <description>&lt;P&gt;This is the correlation search I currently have&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=honeypot sourcetype=cowrie 
| table _time, username, src_ip, eventid, message 
| where eventid!="cowrie.log.closed" 
| where src_ip!="10.11.13.29"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="st1_0-1679930280055.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24557i6FAC3EE0202ECAFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="st1_0-1679930280055.png" alt="st1_0-1679930280055.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="st1_1-1679930293434.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24558i7B7FAB9C021442D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="st1_1-1679930293434.png" alt="st1_1-1679930293434.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example events:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;_time&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="82.8906px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;username&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="97.125px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;src_ip&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="156.312px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;eventid&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="329.562px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;message&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:43&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD: exit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:41&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;root&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.login.success&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;login attempt [root/admin] succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="69px"&gt;2023-03-22 14:25:38&lt;/TD&gt;
&lt;TD width="82.8906px" height="69px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="69px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="69px"&gt;hny.session.connect&lt;/TD&gt;
&lt;TD width="329.562px" height="69px"&gt;New connection: 10.12.8.180:2303 (10.11.131.199:2222) [session: 520a4f7b0870]&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:00&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD:&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:00&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD:&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The correlation search runs every hour and, for the example events shown above, the search is putting out 5 of the same notables (one for each event). How can I have only one notable for each hour? I tried using stats and counting by src_ip but that only returns the fields that have a username.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2023 21:25:14 GMT</pubDate>
    <dc:creator>st1</dc:creator>
    <dc:date>2023-03-27T21:25:14Z</dc:date>
    <item>
      <title>How to generate one notable for multiple events?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-generate-one-notable-for-multiple-events/m-p/636167#M15838</link>
      <description>&lt;P&gt;This is the correlation search I currently have&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=honeypot sourcetype=cowrie 
| table _time, username, src_ip, eventid, message 
| where eventid!="cowrie.log.closed" 
| where src_ip!="10.11.13.29"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="st1_0-1679930280055.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24557i6FAC3EE0202ECAFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="st1_0-1679930280055.png" alt="st1_0-1679930280055.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="st1_1-1679930293434.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24558i7B7FAB9C021442D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="st1_1-1679930293434.png" alt="st1_1-1679930293434.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example events:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;_time&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="82.8906px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;username&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="97.125px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;src_ip&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="156.312px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;eventid&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="329.562px" height="25px"&gt;&lt;FONT color="#0000FF"&gt;message&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:43&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD: exit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:41&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;root&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.login.success&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;login attempt [root/admin] succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="69px"&gt;2023-03-22 14:25:38&lt;/TD&gt;
&lt;TD width="82.8906px" height="69px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="69px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="69px"&gt;hny.session.connect&lt;/TD&gt;
&lt;TD width="329.562px" height="69px"&gt;New connection: 10.12.8.180:2303 (10.11.131.199:2222) [session: 520a4f7b0870]&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:00&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD:&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="108.109px" height="47px"&gt;2023-03-22 14:25:00&lt;/TD&gt;
&lt;TD width="82.8906px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="97.125px" height="47px"&gt;10.12.8.180&lt;/TD&gt;
&lt;TD width="156.312px" height="47px"&gt;hny.command.input&lt;/TD&gt;
&lt;TD width="329.562px" height="47px"&gt;CMD:&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The correlation search runs every hour and, for the example events shown above, the search is putting out 5 of the same notables (one for each event). How can I have only one notable for each hour? I tried using stats and counting by src_ip but that only returns the fields that have a username.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 21:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-generate-one-notable-for-multiple-events/m-p/636167#M15838</guid>
      <dc:creator>st1</dc:creator>
      <dc:date>2023-03-27T21:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate one notable for multiple events?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-generate-one-notable-for-multiple-events/m-p/636238#M15848</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223508"&gt;@st1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Not having a username, or the username being null, will not stop stats counting the results rows by src_ip, so maybe there was something wrong with you original query.&lt;BR /&gt;&lt;BR /&gt;Anyway, here's an a run anywhere example using your sample events provided that groups the results by src_ip.&amp;nbsp; It includes an option to fill in a null username, but this is not required.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="time,username,src_ip,eventid,message
2023-03-22 14:25:43,,10.12.8.180,hny.command.input,CMD: exit
2023-03-22 14:25:41,root,10.12.8.180,hny.login.success,login attempt [root/admin] succeeded
2023-03-22 14:25:38,,10.12.8.180,hny.session.connect,New connection: 10.12.8.180:2303 (10.11.131.199:2222) [session: 520a4f7b0870]
2023-03-22 14:25:00,,10.12.8.180,hny.command.input,CMD:
2023-03-22 14:25:00,,10.12.8.180,hny.command.input,CMD:"
| multikv forceheader=1
| eval _time=strptime(time, "%F %T")
| table _time username src_ip eventid message
 ``` create dummy events above ```
 ``` do SPL the below ```
| fillnull username value="null"
| eval time=strftime(_time, "%F %T")
| stats list(*) AS * BY src_ip&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Side note, it's generally more efficient to filter out data in the base search, e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=honeypot sourcetype=cowrie NOT (eventid="cowrie.log.closed" OR src_ip="10.11.13.29")
| fillnull username value="null"
| eval time=strftime(_time, "%F %T")
| stats list(*) AS * BY src_ip&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 00:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-generate-one-notable-for-multiple-events/m-p/636238#M15848</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-03-28T00:49:29Z</dc:date>
    </item>
  </channel>
</rss>

