<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alert based on data on previous and new event in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88217#M1225</link>
    <description>&lt;P&gt;So this is where I am now&lt;/P&gt;

&lt;P&gt;&lt;A href="http://picpaste.com/pics/splunk-Wz9dmCB4.1303775659.png" target="_blank"&gt;http://picpaste.com/pics/splunk-Wz9dmCB4.1303775659.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I like to generate a table output instead&lt;/P&gt;

&lt;P&gt;user   winscp_release&lt;/P&gt;

&lt;P&gt;pgaul  4.1.8 or even WinSCP_release_4.1.8&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:29:31 GMT</pubDate>
    <dc:creator>vadud3</dc:creator>
    <dc:date>2020-09-28T09:29:31Z</dc:date>
    <item>
      <title>alert based on data on previous and new event</title>
      <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88214#M1222</link>
      <description>&lt;P&gt;Apr 25 17:13:28 www2 sshd[27718]: [ID 800047 auth.debug] debug1: no match: WinSCP_release_4.3.2&lt;/P&gt;

&lt;P&gt;[..within 5 secs..]&lt;/P&gt;

&lt;P&gt;Apr 25 17:13:29 www2 sshd[27718]: [ID 800047 auth.info] Failed none for john from 10.2.43.186 port 1358 ssh2&lt;/P&gt;

&lt;P&gt;So if winscp is below 4.0.4 get an alert saying john is using older release. Because that is&lt;BR /&gt;
sshd2 process 27718 belongs to john.&lt;/P&gt;

&lt;P&gt;How do I correlate between two events, 5+ secs apart, based on the process id and then generate an appropriate alert if a the number portion of the string is below 4.0.4? &lt;/P&gt;

&lt;P&gt;Alert will always go to &lt;A href="mailto:sysadmin@example.com" target="_blank"&gt;sysadmin@example.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88214#M1222</guid>
      <dc:creator>vadud3</dc:creator>
      <dc:date>2020-09-28T09:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: alert based on data on previous and new event</title>
      <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88215#M1223</link>
      <description>&lt;P&gt;with the help of Ayn from #splunk I got this far&lt;/P&gt;

&lt;P&gt;source="sshd.log" | rex field=_raw "sshd[(?&lt;PID&gt;\d+)]: " | transaction pid&lt;/PID&gt;&lt;/P&gt;

&lt;P&gt;So that is a good start&lt;/P&gt;

&lt;P&gt;Also, a separate search like this works, which displays the events where winscp version&lt;BR /&gt;
is lower than 4.0.4&lt;/P&gt;

&lt;P&gt;source="sshd.log" | rex field=&lt;EM&gt;raw &lt;BR /&gt;
 "version WinSCP_release&lt;/EM&gt;(?&lt;MAJOR_VERSION&gt;\d).(?&lt;MINOR_VERSION1&gt;\d).&lt;BR /&gt;
 (?&lt;MINOR_VERSION2&gt;\d)" | &lt;BR /&gt;
  eval version=major_version.minor_version1.minor_version2 | where version &amp;lt; 419&lt;/MINOR_VERSION2&gt;&lt;/MINOR_VERSION1&gt;&lt;/MAJOR_VERSION&gt;&lt;/P&gt;

&lt;P&gt;Now if both events has the same pid then display the event that happens in next 60s&lt;BR /&gt;
with same pid and has the username displayed like below&lt;/P&gt;

&lt;P&gt;Here is an exerpt of the log&lt;/P&gt;

&lt;P&gt;&lt;A href="http://pastebin.com/WNtyaJDN" target="_blank"&gt;http://pastebin.com/WNtyaJDN&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is the result should look like&lt;/P&gt;

&lt;P&gt;Apr 20 16:17:11 www2 sshd[10895]: [ID 800047 auth.debug] debug1: userauth-request for user pgaul service ssh-connection method none&lt;/P&gt;

&lt;P&gt;because user pgaul using an winscp whose version is higher than 4.2.0&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88215#M1223</guid>
      <dc:creator>vadud3</dc:creator>
      <dc:date>2020-09-28T09:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: alert based on data on previous and new event</title>
      <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88216#M1224</link>
      <description>&lt;P&gt;looks like this gave me what I wanted..&lt;/P&gt;

&lt;P&gt;source="sshd.log" | rex field=&lt;EM&gt;raw "sshd[(?&lt;PID&gt;\d+)]: " | transaction pid maxspan=60s | search winscp | rex field=_raw "version WinSCP_release&lt;/PID&gt;&lt;/EM&gt;(?&lt;MAJOR_VERSION&gt;\d).(?&lt;MINOR_VERSION1&gt;\d).(?&lt;MINOR_VERSION2&gt;\d)" | eval version=major_version.minor_version1.minor_version2 | where version &amp;lt; 423&lt;/MINOR_VERSION2&gt;&lt;/MINOR_VERSION1&gt;&lt;/MAJOR_VERSION&gt;&lt;/P&gt;

&lt;P&gt;any suggestion on how to improve it appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88216#M1224</guid>
      <dc:creator>vadud3</dc:creator>
      <dc:date>2020-09-28T09:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: alert based on data on previous and new event</title>
      <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88217#M1225</link>
      <description>&lt;P&gt;So this is where I am now&lt;/P&gt;

&lt;P&gt;&lt;A href="http://picpaste.com/pics/splunk-Wz9dmCB4.1303775659.png" target="_blank"&gt;http://picpaste.com/pics/splunk-Wz9dmCB4.1303775659.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I like to generate a table output instead&lt;/P&gt;

&lt;P&gt;user   winscp_release&lt;/P&gt;

&lt;P&gt;pgaul  4.1.8 or even WinSCP_release_4.1.8&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88217#M1225</guid>
      <dc:creator>vadud3</dc:creator>
      <dc:date>2020-09-28T09:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: alert based on data on previous and new event</title>
      <link>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88218#M1226</link>
      <description>&lt;P&gt;ok so I "improved" the search&lt;/P&gt;

&lt;P&gt;source="sshd.log" | rex field=&lt;EM&gt;raw "sshd[(?&lt;PID&gt;\d+)]: " | transaction pid maxspan=60s | search winscp or accepted | rex field=_raw "version WinSCP_release&lt;/PID&gt;&lt;/EM&gt;(?&lt;MAJV&gt;\d).(?&lt;MINV1&gt;\d).(?&lt;MINV2&gt;\d)" | eval version=majv.minv1.minv2 | where version &amp;lt; 423 | rex "for (?&lt;USER&gt;[^ ]+) from" | eval ver=majv.".".minv1.".".minv2 | eval date=date_month."/".date_mday."/".date_year| table user ver date&lt;/USER&gt;&lt;/MINV2&gt;&lt;/MINV1&gt;&lt;/MAJV&gt;&lt;/P&gt;

&lt;P&gt;looking for a suggestion to improve this search.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-based-on-data-on-previous-and-new-event/m-p/88218#M1226</guid>
      <dc:creator>vadud3</dc:creator>
      <dc:date>2020-09-28T09:29:51Z</dc:date>
    </item>
  </channel>
</rss>

