Alerting

How to create an alert of a trend Analysis on the same time over a period of time?

srisahitya_v
Communicator

Hello All,

I would like to write a query for an IP which is targeting every day to my system. I would like to make a trend diagram OR alert to showcase these kind of IP's.

But with time chart command, I am unable to fulfill the need.

Example: one IP is scanning my system, every day at 8'O clock in the morning for past 7 days. Then it should trigger an alert.

with time chart I can make the time line with spikes, but not able to trigger alert for above one.

any suggestion?

0 Karma

srisahitya_v
Communicator

@mayurr98:

the query is "index=firewall_log | timechart span=1h count BY IP"
It gives a time line only.

What I need is that an alert should trigger, when a suspicious IP making trend of is accessing my network, "every day same time over a period of time"

Any suggestions?

0 Karma

mayurr98
Super Champion

what is your timechart query?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...