<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating alarms based on differences in stats output in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190449#M54849</link>
    <description>&lt;P&gt;My be something like this will work.&lt;/P&gt;

&lt;H2&gt;search/stats to get "byte sent" for current hour per host | table host,byteSentCurrent ##| join host [##search/stats to## get avg "byte sent" for past 1 day or any other period per host | table host, avgByteSent##] | ##compare percent difference between byteSentCurrent and avgByteSent and alert based on that&lt;/H2&gt;</description>
    <pubDate>Thu, 21 Aug 2014 18:53:22 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-08-21T18:53:22Z</dc:date>
    <item>
      <title>Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190446#M54846</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;

&lt;P&gt;Right now we're monitoring connections between internal IPs and external IPs using our proxy log input.&lt;/P&gt;

&lt;P&gt;We monitor total bytes sent, average bytes sent, mode bytes sent, STDVE bytes sent, var bytes sent, and range bytes sent using the Eventstats search.&lt;/P&gt;

&lt;P&gt;This report is ran every hour. &lt;/P&gt;

&lt;P&gt;What I would like to do is set up an alarm if there's some kind of statistical anomaly regarding the data being sent. For example, Host 1 averages 10mb of traffic every hour over HTTP. Host 1 becomes compromised and there's a massive data exfil that sends the average per hour to 1GB.&lt;/P&gt;

&lt;P&gt;How can we setup some kind threshold to alert us of a massive deviation from the normal range?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2014 16:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190446#M54846</guid>
      <dc:creator>sknot1454</dc:creator>
      <dc:date>2014-08-21T16:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190447#M54847</link>
      <description>&lt;P&gt;I would recommend watching Jesse Trucks on trending and stddev etc. &lt;BR /&gt;
&lt;A href="http://vimeo.com/66779015"&gt;http://vimeo.com/66779015&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2014 17:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190447#M54847</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2014-08-21T17:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190448#M54848</link>
      <description>&lt;P&gt;Informative video, thanks.&lt;/P&gt;

&lt;P&gt;Unfortunately, he's looking at it from a much higher view than I am. I don't care about total events generated by a sourcetype. I care more about trending a single field value e.g "bytes sent" and the deviation from that.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2014 18:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190448#M54848</guid>
      <dc:creator>sknot1454</dc:creator>
      <dc:date>2014-08-21T18:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190449#M54849</link>
      <description>&lt;P&gt;My be something like this will work.&lt;/P&gt;

&lt;H2&gt;search/stats to get "byte sent" for current hour per host | table host,byteSentCurrent ##| join host [##search/stats to## get avg "byte sent" for past 1 day or any other period per host | table host, avgByteSent##] | ##compare percent difference between byteSentCurrent and avgByteSent and alert based on that&lt;/H2&gt;</description>
      <pubDate>Thu, 21 Aug 2014 18:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190449#M54849</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-21T18:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190450#M54850</link>
      <description>&lt;P&gt;I think I have a decent solution now.&lt;/P&gt;

&lt;P&gt;I'm just going to have to create a query that looks at avg(byes_sent) per minute for a particular host type(web server,DC,IIS, etc). Monitor that query every day for like a week and drill down a predictable average and calculate the STDEV from that.&lt;/P&gt;

&lt;P&gt;Based off of that STDEV, I can create a search query with a WHERE statement that says "return results where STDEV &amp;gt; baseline". If the query brings back any results, fire off an alarm.&lt;/P&gt;

&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 13:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190450#M54850</guid>
      <dc:creator>sknot1454</dc:creator>
      <dc:date>2014-08-22T13:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Creating alarms based on differences in stats output</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190451#M54851</link>
      <description>&lt;P&gt;A straightforward solution would be to run:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | prelertautodetect sum(bytes_sent) by host_type
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This would baseline the total bytes sent from each host_type (accounting for periodicity and behaviour not well described by STDEV and MEAN etc.) and create an anomaly where a specific host_type sends unusual volumes of data.&lt;/P&gt;

&lt;P&gt;An issue with this analysis is that if there are a large number of hosts of a particular host_type, then a deviation of one host may be lost in the aggregation. &lt;/P&gt;

&lt;P&gt;Therefore, an extension to this could be to partition the hosts by type and then analyse each host in that partition. For example,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | prelertautodetect partitionfield=host_type sum(bytes_sent) over host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In this analysis, a statistical profile is created for each host_type and each host is compared to this profile.&lt;/P&gt;

&lt;P&gt;All these searches can be run continuously in real-time.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-alarms-based-on-differences-in-stats-output/m-p/190451#M54851</guid>
      <dc:creator>prelert</dc:creator>
      <dc:date>2020-09-28T17:28:31Z</dc:date>
    </item>
  </channel>
</rss>

