<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Show events with certain frequency in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423229#M173424</link>
    <description>&lt;P&gt;Hi can you try this :&lt;/P&gt;

&lt;P&gt;Number of Password Attacks:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;your_index&amp;gt; | rex field=_raw "\s"(GET|POST|DELETE|UPDATE)\s\/(?&amp;lt;Access&amp;gt;[^\.]+)" | search Access=login | stats count as "Password Attacks"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Plotting it in Timechart:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;your_index&amp;gt; | rex field=_raw "\s"(GET|POST|DELETE|UPDATE)\s\/(?&amp;lt;Access&amp;gt;[^\.]+)" | search Access=login | timechart span=3s count as "Password Attacks"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;change span according to your need.&lt;BR /&gt;
let me know if this helps!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 08:44:01 GMT</pubDate>
    <dc:creator>mayurr98</dc:creator>
    <dc:date>2019-01-24T08:44:01Z</dc:date>
    <item>
      <title>Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423228#M173423</link>
      <description>&lt;P&gt;Hi guys, I have an Apache log (with only few information) and I would like to find out the possible events related to brute force password attack.&lt;/P&gt;

&lt;P&gt;I am considering to find the login page access records which happened rapidly within three seconds. For example (just an example), if there are the following events:&lt;/P&gt;

&lt;P&gt;127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:35 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:35 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:34 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:34 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:33 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:32 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:32 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;"&lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:20:36 -0700] "GET /config.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/dashboard.php"&gt;http://www.example.com/dashboard.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:10:00 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;"&lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:20 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:20 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:19 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:18 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;/P&gt;

&lt;P&gt;The result will be:&lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:35 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:35 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:34 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:34 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:33 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:32 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:55:32 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;"&lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:20 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:20 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:19 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;BR /&gt;
127.0.0.1 - frank [10/Oct/2000:13:08:18 -0700] "GET /login.php HTTP/1.0" 200 2326 "&lt;A href="http://www.example.com/login.php"&gt;http://www.example.com/login.php&lt;/A&gt;" &lt;/P&gt;

&lt;P&gt;What should the code be?&lt;BR /&gt;
I will be able to count the number of password attack occur and plot a time chart showing the  attack pattern, after solving this problem.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 07:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423228#M173423</guid>
      <dc:creator>ernestpoon</dc:creator>
      <dc:date>2019-01-24T07:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423229#M173424</link>
      <description>&lt;P&gt;Hi can you try this :&lt;/P&gt;

&lt;P&gt;Number of Password Attacks:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;your_index&amp;gt; | rex field=_raw "\s"(GET|POST|DELETE|UPDATE)\s\/(?&amp;lt;Access&amp;gt;[^\.]+)" | search Access=login | stats count as "Password Attacks"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Plotting it in Timechart:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;your_index&amp;gt; | rex field=_raw "\s"(GET|POST|DELETE|UPDATE)\s\/(?&amp;lt;Access&amp;gt;[^\.]+)" | search Access=login | timechart span=3s count as "Password Attacks"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;change span according to your need.&lt;BR /&gt;
let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 08:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423229#M173424</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-01-24T08:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423230#M173425</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;did you try to use &lt;CODE&gt;| timechart count span=3s&lt;/CODE&gt; ? This will give you a lot of spikes in timechart graph but it will group your events in a 3 s intervall. You should only use this with a short time periode&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 08:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423230#M173425</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-24T08:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423231#M173426</link>
      <description>&lt;P&gt;Hi, thank you for your advice. &lt;STRONG&gt;timechart span=3s count as "Password Attacks"&lt;/STRONG&gt; is useful! However, it seems that the rex part has some mistakes so there's an error telling me "Search Factory: Unknown search command 'post'."&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 02:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423231#M173426</guid>
      <dc:creator>ernestpoon</dc:creator>
      <dc:date>2019-01-25T02:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423232#M173427</link>
      <description>&lt;P&gt;Try this : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;your_index&amp;gt; | rex field=_raw "\s\"GET\s\/(?&amp;lt;Access&amp;gt;[^\.]+)" | search Access=login | timechart span=3s count as "Password Attacks"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 Jan 2019 05:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423232#M173427</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-01-25T05:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Show events with certain frequency</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423233#M173428</link>
      <description>&lt;P&gt;The error disappeared. But no result is shown.&lt;BR /&gt;
I am now trying specify the url_path instead of using regular expression.  However, I cannot save the timechart to a dashboard. Do you know why?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 09:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-events-with-certain-frequency/m-p/423233#M173428</guid>
      <dc:creator>ernestpoon</dc:creator>
      <dc:date>2019-01-25T09:31:58Z</dc:date>
    </item>
  </channel>
</rss>

