<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two time condition searches – please help. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670668#M229893</link>
    <description>&lt;P&gt;I believe it doesn't show correct results. I mean, sometimes it shows one event in count for source IP, I presume should be min 5. Or I missed something?&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 16:17:57 GMT</pubDate>
    <dc:creator>PiotrAp</dc:creator>
    <dc:date>2023-12-04T16:17:57Z</dc:date>
    <item>
      <title>Two time condition searches – please help.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670660#M229889</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I’m trying to create two searches and having some problems. I hope somebody could help me with this.&lt;/P&gt;&lt;P&gt;1. 7 or more IDS Alerts from a single IP Address in one minute.&lt;/P&gt;&lt;P&gt;I created something like below, but it doesn’t seem to be working correctly:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index=ids&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;| streamstats count time_window=1m by src_ip&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;| where count &amp;gt;=7&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;| stats values(dest_ip) as "Destination IP" values(attack) as "Attack" values(severity) as "Severity" values(host) as "FW" count by "Source IP"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;2. 5 or more hosts in 1h attacked with the same IDS Signature&lt;/P&gt;&lt;P&gt;This seems to be even more complex as it has 3 conditions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;5 hosts&lt;/LI&gt;&lt;LI&gt;1h&lt;/LI&gt;&lt;LI&gt;The same IPS signature&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, I’m not sure how to even start after failing first one.&lt;/P&gt;&lt;P&gt;Could somebody help me with this please?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 15:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670660#M229889</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2023-12-04T15:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Two time condition searches – please help.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670666#M229892</link>
      <description>&lt;P&gt;What is incorrect about the first search?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670666#M229892</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-04T16:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Two time condition searches – please help.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670668#M229893</link>
      <description>&lt;P&gt;I believe it doesn't show correct results. I mean, sometimes it shows one event in count for source IP, I presume should be min 5. Or I missed something?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Two-time-condition-searches-please-help/m-p/670668#M229893</guid>
      <dc:creator>PiotrAp</dc:creator>
      <dc:date>2023-12-04T16:17:57Z</dc:date>
    </item>
  </channel>
</rss>

