<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with a custom co-relation search!!!! in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449510#M171441</link>
    <description>&lt;P&gt;Like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | spath
| stats values(final_action) AS final_action dc(final_action) As final_action_count BY guid
| where final_action_count &amp;gt; 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 12 May 2019 04:36:08 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-05-12T04:36:08Z</dc:date>
    <item>
      <title>Help with a custom co-relation search!!!!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449508#M171439</link>
      <description>&lt;P&gt;I'm having a problem creating an alert for following scenario:&lt;/P&gt;

&lt;P&gt;Data source: index=mail sourcetype=pps_messagelog (interesting fields = guid, final_action). Basically I want a search which would fire up an alert whenever there are events which have same "guid" but more than one "final_action". Or, in another way, if there is an event with "final_action=continue", which matches an event with "final_action=discard", with SAME "guid" being the matching criteria.&lt;/P&gt;

&lt;P&gt;Sample Data:&lt;/P&gt;

&lt;P&gt;{"guid": "Irhblj4vS9DsfIwHAFbT8pbzf2mZQISa", "msg": {"parsedAddresses": {"to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": ["&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"]}, "lang": "en", "sizeBytes": 26337, "normalizedHeader": {"subject": ["[EXT] Subject of email"], "message-id": ["1423317795.5042.1557254884493@brms-prd1-25"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}, "header": {"subject": ["Subject of email"], "message-id": ["&lt;A href="mailto:1423317795.5042.1557254884493@brms-prd1-25" target="_blank"&gt;1423317795.5042.1557254884493@brms-prd1-25&lt;/A&gt;"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \r\n\&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}}, "action_spf": [{"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}], "final_rule": "pass", "ts": "2019-05-07T12:48:05.173614-0600", "connection": {"tls": {"inbound": {"cipher": "ECDHE-RSA-AES256-GCM-SHA384", "cipherBits": 256, "version": "TLSv1.2"}}, "helo": "alln-app-2.cisco.com", "country": "us", "sid": "2sbeggg6s0", "protocol": "smtp:smtp", "ip": "173.37.142.87", "resolveStatus": "ok", "host": "alln-app-2.cisco.com"}, "pps": {"cid": "agrium_hosted", "agent": "m0046467.ppops.net", "version": "8.11.10.11"}, "envelope": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "action_dkimv": [], "final_module": "pdr", "action_dmarc": [{"action": "continue", "rule": "pass", "module": "dmarc"}], "msgParts": [{"detectedName": "text.html", "labeledName": "text.html", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTVjZWE4KQ==\n", "detectedSizeBytes": 17794, "labeledMime": "text/html", "sizeDecodedBytes": 17794, "isVirtual": false, "metadata": {}, "labeledCharset": "UTF-8", "sha256": "5029cc915965d0140e2d0ba88c2ae297c278d3a6c1c8b9c228bf515b8b8ab80c", "md5": "cab46e55f172b2b13f9db709cd3bc4db", "detectedExt": "HTML", "disposition": "inline", "isCorrupted": false, "isDeleted": false, "detectedCharset": "UTF-8", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2VmZjE3YTAwKQ==\n", "isProtected": false, "structureId": "0", "urls": [{"src": ["urldefense"], "url": "&lt;A href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://www.cisco.com" target="_blank"&gt;http://www.cisco.com&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home/?OrderNumber=800127380" target="_blank"&gt;https://ibpm.cisco.com/rma/home/?OrderNumber=800127380&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home" target="_blank"&gt;https://ibpm.cisco.com/rma/home&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165" target="_blank"&gt;http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165&lt;/A&gt;", "isRewritten": true}], "labeledExt": "html", "isTimedOut": false, "detectedMime": "text/html"}, {"detectedName": "webwb/cisconewlogo.png", "labeledName": "webwb/cisconewlogo.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTAyN2QwKQ==\n", "detectedSizeBytes": 2075, "labeledMime": "image/png", "sizeDecodedBytes": 2075, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "bb699845aa6f18f0baf339ea3969597abcfdfebb77956efebc5de2d6e1e90c10", "md5": "c6c532f7ebb183c4af68a2d8e320a4ad", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzNGRlM2UyMmQ4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}, {"detectedName": "webwb/call_icon.png", "labeledName": "webwb/call_icon.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MDE2MzYwKQ==\n", "detectedSizeBytes": 404, "labeledMime": "image/png", "sizeDecodedBytes": 404, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "d66320e32e99380d33a5cc9212c4216d4ce1c50d34d345b973f4c616a7d7c877", "md5": "dc27600bcf8b5e4cdd882dd4b03eb9ff", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2U4MTc1NTk4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}], "final_action": "continue", "filter": {"suborgs": {"sender": "0", "rcpts": ["0"]}, "verified": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"]}, "qid": "x47IiaKB013302", "quarantine": {"rule": "", "folder": ""}, "modules": {"pdr": {"v2": {"response": "pass"}}, "dkimv": [{"selector": "app", "domain": "cisco.com", "result": "pass"}], "spf": {"domain": "cisco.com", "result": "pass"}, "spam": {"scores": {"classifiers": {"mlx": 0, "impostor": 0, "spam": 0, "adult": 0, "phish": 0, "bulk": 0, "lowpriority": 0, "suspect": 5, "mlxlog": 999, "malware": 0}, "overall": 0}}, "dmarc": {"records": [{"query": "_dmarc.cisco.com", "record": "v=DMARC1; p=quarantine; pct=0; fo=1; ri=3600; rua=mailto:&lt;A href="mailto:cisco@rua.agari.com" target="_blank"&gt;cisco@rua.agari.com&lt;/A&gt;; ruf=mailto:&lt;A href="mailto:cisco@ruf.agari.com" target="_blank"&gt;cisco@ruf.agari.com&lt;/A&gt;"}], "authResults": [{"emailIdentities": {"smtp.mailfrom": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "result": "pass", "method": "spf"}, {"result": "pass", "propspec": {"header.s": "app", "header.d": "cisco.com"}, "method": "dkim"}, {"emailIdentities": {"header.from": "cisco.com"}, "result": "pass", "method": "dmarc"}], "alignment": [{"from_domain": "cisco.com", "spf": {"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}, "dkim": [{"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}]}], "srvid": "agrium.com", "filterdResult": "pass"}, "zerohour": {"score": "unknown"}, "urldefense": {"counts": {"unique": 5, "total": 6, "rewritten": 6}, "version": {"engine": "15"}}}, "durationSecs": 0.581787, "routes": ["default_inbound"], "isMsgReinjected": false, "disposition": "continue", "msgSizeBytes": 28953, "isMsgEncrypted": false, "routeDirection": "inbound", "actions": [{"action": "continue", "rule": "pass", "isFinal": true, "module": "pdr"}, {"action": "set-header", "rule": "EXT_add_tag", "module": "access"}, {"action": "continue", "rule": "EXT_add_tag", "module": "access"}, {"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}, {"action": "add-header", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "pass", "module": "dmarc"}, {"action": "add-header", "rule": "inbound_notspam", "module": "spam"}], "startTime": "2019-05-07T12:48:05.173614-0600"}} &lt;/P&gt;

&lt;P&gt;Any leads will be much appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449508#M171439</guid>
      <dc:creator>swaguzari</dc:creator>
      <dc:date>2020-09-30T00:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help with a custom co-relation search!!!!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449509#M171440</link>
      <description>&lt;P&gt;How do you want the output to look on your alert?  If your goal is to find any guid with &amp;gt;1 final_action this will alert on that:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=mail sourcetype=pps_messagelog
| stats dc(final_action) as final_actions by guid
| search final_actions&amp;gt;1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 May 2019 19:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449509#M171440</guid>
      <dc:creator>dmarling</dc:creator>
      <dc:date>2019-05-08T19:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with a custom co-relation search!!!!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449510#M171441</link>
      <description>&lt;P&gt;Like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | spath
| stats values(final_action) AS final_action dc(final_action) As final_action_count BY guid
| where final_action_count &amp;gt; 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 12 May 2019 04:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449510#M171441</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-12T04:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Help with a custom co-relation search!!!!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449511#M171442</link>
      <description>&lt;P&gt;Hi @swaguzari,&lt;/P&gt;

&lt;P&gt;You're looking for something like this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=mail sourcetype=pps_messagelog (final_action=continue OR final_action=discard)
| stats dc(final_action) as nubmer_of_final_action by guid
| where nubmer_of_final_action &amp;gt; 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will give you any guid that is seen more than one with both values continue and discard for final_action.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 15:21:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-a-custom-co-relation-search/m-p/449511#M171442</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-12T15:21:40Z</dc:date>
    </item>
  </channel>
</rss>

