Alerting

How to create an alert of a trend Analysis on the same time over a period of time?

srisahitya_v
Communicator

Hello All,

I would like to write a query for an IP which is targeting every day to my system. I would like to make a trend diagram OR alert to showcase these kind of IP's.

But with time chart command, I am unable to fulfill the need.

Example: one IP is scanning my system, every day at 8'O clock in the morning for past 7 days. Then it should trigger an alert.

with time chart I can make the time line with spikes, but not able to trigger alert for above one.

any suggestion?

0 Karma

srisahitya_v
Communicator

@mayurr98:

the query is "index=firewall_log | timechart span=1h count BY IP"
It gives a time line only.

What I need is that an alert should trigger, when a suspicious IP making trend of is accessing my network, "every day same time over a period of time"

Any suggestions?

0 Karma

mayurr98
Super Champion

what is your timechart query?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...