Alerting

How to collect specific data from global list and alert anomalies? Transactions analysis

username_forbid
New Member

Hi everybody!

I know that my question could sounds primitive for senior Splunkers but I don't have other way to get needed knowledge.

I have to make transaction analysis mechanism in my company which can be able to catch and alert every anomaly in transaction value - it will be the first indicator of fraud.

At first I'll describe the structure of data what I have.

alt text

As you see there is four data fields. Operation timestamp, operation name, username and amount of transaction. It's enough data for this level of analysis.

What I want to do is to collect transaction value for each client from this table and then using this values to calculate "normal" value for each client_id.

Let's assume that model of "normal" value is just average value for each client_id.

I want to be alerted in every case when this "normal" value for each client_id will be exceeded in new event.

It's the simplest antifraud mechanism ever but enough for our scale of working. I don't have idea how to do it well. Can You help me and tell which commands, functions and syntax I need to interest of to do it? I'll be pleased for every little answer from You.

I'm begginer Splunk user but I hope someday I also could answer here for other begginers question. 🙂

Have a nice day and answer please!

KF

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...