<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write SPL for DLP alert use case using eval in Splunk ES? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-SPL-for-DLP-alert-use-case-using-eval-in-Splunk-ES/m-p/638317#M221235</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;Could anyone over here&amp;nbsp; able to write an spl query for usecase in splunk ES like when single user triggers alert say other than dlp&amp;nbsp; in between 2 hours of time more than 3 times,how to make &amp;nbsp;a count for alert_name&lt;BR /&gt;not for generic events, how to write this use case spl query using eval ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 20:00:35 GMT</pubDate>
    <dc:creator>AL3Z</dc:creator>
    <dc:date>2023-04-03T20:00:35Z</dc:date>
    <item>
      <title>How to write SPL for DLP alert use case using eval in Splunk ES?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-SPL-for-DLP-alert-use-case-using-eval-in-Splunk-ES/m-p/638317#M221235</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Could anyone over here&amp;nbsp; able to write an spl query for usecase in splunk ES like when single user triggers alert say other than dlp&amp;nbsp; in between 2 hours of time more than 3 times,how to make &amp;nbsp;a count for alert_name&lt;BR /&gt;not for generic events, how to write this use case spl query using eval ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 20:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-SPL-for-DLP-alert-use-case-using-eval-in-Splunk-ES/m-p/638317#M221235</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-04-03T20:00:35Z</dc:date>
    </item>
  </channel>
</rss>

