<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use  the condition stanza in this spl query? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636479#M221041</link>
    <description>&lt;P&gt;Hi, I'm trying to find the alerts by user between the period of 2 hours like Alert1,Alert2 Here I need a spl query for this condition&lt;BR /&gt;* And one more condition spl is&amp;nbsp; In bwtween 2hours if there is an alert for&amp;nbsp; single user more than 3 times it should raise an alert.&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2023 16:06:30 GMT</pubDate>
    <dc:creator>AL3Z</dc:creator>
    <dc:date>2023-03-29T16:06:30Z</dc:date>
    <item>
      <title>How to use  the condition stanza in this spl query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636479#M221041</link>
      <description>&lt;P&gt;Hi, I'm trying to find the alerts by user between the period of 2 hours like Alert1,Alert2 Here I need a spl query for this condition&lt;BR /&gt;* And one more condition spl is&amp;nbsp; In bwtween 2hours if there is an alert for&amp;nbsp; single user more than 3 times it should raise an alert.&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 16:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636479#M221041</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-29T16:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636520#M221054</link>
      <description>&lt;P&gt;What have you tried so far and what results did you get?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 12:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636520#M221054</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-29T12:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636540#M221061</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi,&lt;BR /&gt;Use case :1&lt;BR /&gt;&lt;BR /&gt;If the user triggers pdm and encrypt alerts both in a period of 2 hours it should raise an alert.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AL3Z_0-1680098490570.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24614i7D6AD6929B96C3CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AL3Z_0-1680098490570.jpeg" alt="AL3Z_0-1680098490570.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use case:2&lt;BR /&gt;&lt;BR /&gt;If the user triggers other than pdm in between&amp;nbsp; 2 hours&amp;nbsp; for single user more than 3 times it should raise an alert .&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AL3Z_3-1680098543040.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24618iC566CF2D74D7C446/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AL3Z_3-1680098543040.jpeg" alt="AL3Z_3-1680098543040.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 14:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636540#M221061</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-29T14:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636569#M221078</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please have a look on usecase snapshot once.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 18:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636569#M221078</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-29T18:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636579#M221083</link>
      <description>&lt;P&gt;You have the searches so what is preventing you from saving them as alerts?&amp;nbsp; Click "Save as" in the top-right corner of the search to make it into an alert.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 20:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636579#M221083</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-29T20:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636605#M221089</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My aim is creating a correlation search..&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 23:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636605#M221089</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-29T23:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636708#M221119</link>
      <description>&lt;P&gt;In Enterprise Security, go to Configure-&amp;gt;Content-&amp;gt;Content Management then click the "Create New Content" button and select Correlation Search.&amp;nbsp; Copy-and-paste your search from the S&amp;amp;R window into the Search box of the CS.&amp;nbsp; Complete the rest of the CS form and click Save.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 13:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636708#M221119</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-30T13:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636749#M221136</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;what I'm trying to do is like&lt;BR /&gt;&lt;BR /&gt;usecase1:&amp;nbsp;&amp;nbsp;alert_name!="*pdm*"&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; by user&lt;BR /&gt;&lt;BR /&gt;base search&lt;BR /&gt;--------------&lt;BR /&gt;| eval non_pdm_alert=if(alert_name!="*pdm*", 1, 0)&lt;BR /&gt;| sort _time&lt;BR /&gt;| streamstats count(non_pdm_alert) AS non_pdm_count by user time_window=2h&lt;BR /&gt;| where non_pdm_count&amp;gt;2&lt;BR /&gt;&lt;BR /&gt;It is not giving desired output.&lt;BR /&gt;&lt;BR /&gt;usecase 2:&amp;nbsp;(alert_name="*PDM*" AND alert_name="*encrypted*")&lt;/P&gt;&lt;P&gt;base search&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| eval both_alerts_triggered=if(alert_name="*pdm*" AND alert_name="*encrypted*", 1, 0)&lt;BR /&gt;&lt;/SPAN&gt;| sort _time&lt;BR /&gt;| streamstats count(eval(both_alerts_triggered=1)) AS triggered_count by user time_window=2h&lt;BR /&gt;| where triggered_count&amp;gt;=2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 17:11:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636749#M221136</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-30T17:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636766#M221137</link>
      <description>&lt;P&gt;I'm uncertain about what the ask.&amp;nbsp; First you asked for alerts.&amp;nbsp; Then you shared your searches and asked how to make them into correlation searches.&amp;nbsp; Now you share more searches and say the output is not what is desired.&amp;nbsp; Just what &lt;STRONG&gt;is&lt;/STRONG&gt; desired?&amp;nbsp; How are the existing searches not meeting expectations?&amp;nbsp; What are those expectations?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 19:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636766#M221137</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-30T19:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636792#M221141</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ask is if the user triggers both the alerts i.e pdm and encrypted with in a span of 2 hours.&lt;/P&gt;&lt;P&gt;Other one is if the user triggers non pdm alerts with in a span of 2 hours is my requirement&lt;/P&gt;&lt;P&gt;Please edit the above search as per the usecase.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 01:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/636792#M221141</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-03-31T01:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to use  the condition stanza in this spl query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/638256#M221223</link>
      <description>&lt;P&gt;Alerts are independent.&amp;nbsp; There is no test for triggering more than one alert (unless you're using Enterprise Security).&amp;nbsp; One alert would have to test for both (or more) conditions and trigger if all are met.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 14:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-the-condition-stanza-in-this-spl-query/m-p/638256#M221223</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-02T14:53:51Z</dc:date>
    </item>
  </channel>
</rss>

