<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to calculate time between events for the past month in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-to-calculate-time-between-events-for-the-past-month/m-p/492852#M8428</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have an index for a symantec produt, and I have to write a search to alert if any of the sourcetypes doesn't get any data in for a certain amount of time.&lt;/P&gt;

&lt;P&gt;Calculating the time is a little tricky for me, since it has to ba searches this way:&lt;/P&gt;

&lt;P&gt;Searching for the time differences between all events by sourcetypes for the last month, and make a summary of it.&lt;/P&gt;

&lt;P&gt;The alert should apear everytime the index won't get data from a certain sourcetype for longer time than the result from the search above.&lt;/P&gt;

&lt;P&gt;I would realy love to get some help,&lt;BR /&gt;
thank you! &lt;/P&gt;</description>
    <pubDate>Sun, 24 Nov 2019 12:33:14 GMT</pubDate>
    <dc:creator>sabinayousoubuv</dc:creator>
    <dc:date>2019-11-24T12:33:14Z</dc:date>
    <item>
      <title>how to calculate time between events for the past month</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-to-calculate-time-between-events-for-the-past-month/m-p/492852#M8428</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have an index for a symantec produt, and I have to write a search to alert if any of the sourcetypes doesn't get any data in for a certain amount of time.&lt;/P&gt;

&lt;P&gt;Calculating the time is a little tricky for me, since it has to ba searches this way:&lt;/P&gt;

&lt;P&gt;Searching for the time differences between all events by sourcetypes for the last month, and make a summary of it.&lt;/P&gt;

&lt;P&gt;The alert should apear everytime the index won't get data from a certain sourcetype for longer time than the result from the search above.&lt;/P&gt;

&lt;P&gt;I would realy love to get some help,&lt;BR /&gt;
thank you! &lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 12:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-to-calculate-time-between-events-for-the-past-month/m-p/492852#M8428</guid>
      <dc:creator>sabinayousoubuv</dc:creator>
      <dc:date>2019-11-24T12:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: how to calculate time between events for the past month</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-to-calculate-time-between-events-for-the-past-month/m-p/492853#M8429</link>
      <description>&lt;P&gt;Don't reinvent the wheel; this has been solved many times including:&lt;BR /&gt;
Meta Woot!: &lt;A href="https://splunkbase.splunk.com/app/2949/"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&lt;BR /&gt;
TrackMe: &lt;A href="https://splunkbase.splunk.com/app/4621/"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;,&lt;BR /&gt;
Broken Hosts App for Splunk: &lt;A href="https://splunkbase.splunk.com/app/3247/"&gt;https://splunkbase.splunk.com/app/3247/&lt;/A&gt;&lt;BR /&gt;
Alerts for Splunk Admins ("ForwarderLevel" alerts): &lt;A href="https://splunkbase.splunk.com/app/3796/"&gt;https://splunkbase.splunk.com/app/3796/&lt;/A&gt;&lt;BR /&gt;
Splunk Security Essentials(&lt;A href="https://docs.splunksecurityessentials.com/features/sse_data_availability/):"&gt;https://docs.splunksecurityessentials.com/features/sse_data_availability/):&lt;/A&gt; &lt;A href="https://splunkbase.splunk.com/app/3435/"&gt;https://splunkbase.splunk.com/app/3435/&lt;/A&gt;&lt;BR /&gt;
Monitoring Console: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring&lt;/A&gt;&lt;BR /&gt;
Deployment Server: &lt;A href="https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings"&gt;https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:29:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-to-calculate-time-between-events-for-the-past-month/m-p/492853#M8429</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-25T05:29:57Z</dc:date>
    </item>
  </channel>
</rss>

