Alerting

How to collect specific data from global list and alert anomalies? Transactions analysis

username_forbid
New Member

Hi everybody!

I know that my question could sounds primitive for senior Splunkers but I don't have other way to get needed knowledge.

I have to make transaction analysis mechanism in my company which can be able to catch and alert every anomaly in transaction value - it will be the first indicator of fraud.

At first I'll describe the structure of data what I have.

alt text

As you see there is four data fields. Operation timestamp, operation name, username and amount of transaction. It's enough data for this level of analysis.

What I want to do is to collect transaction value for each client from this table and then using this values to calculate "normal" value for each client_id.

Let's assume that model of "normal" value is just average value for each client_id.

I want to be alerted in every case when this "normal" value for each client_id will be exceeded in new event.

It's the simplest antifraud mechanism ever but enough for our scale of working. I don't have idea how to do it well. Can You help me and tell which commands, functions and syntax I need to interest of to do it? I'll be pleased for every little answer from You.

I'm begginer Splunk user but I hope someday I also could answer here for other begginers question. 🙂

Have a nice day and answer please!

KF

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...