Alerting

How to create an alert of a trend Analysis on the same time over a period of time?

srisahitya_v
Communicator

Hello All,

I would like to write a query for an IP which is targeting every day to my system. I would like to make a trend diagram OR alert to showcase these kind of IP's.

But with time chart command, I am unable to fulfill the need.

Example: one IP is scanning my system, every day at 8'O clock in the morning for past 7 days. Then it should trigger an alert.

with time chart I can make the time line with spikes, but not able to trigger alert for above one.

any suggestion?

0 Karma

srisahitya_v
Communicator

@mayurr98:

the query is "index=firewall_log | timechart span=1h count BY IP"
It gives a time line only.

What I need is that an alert should trigger, when a suspicious IP making trend of is accessing my network, "every day same time over a period of time"

Any suggestions?

0 Karma

mayurr98
Super Champion

what is your timechart query?

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...