Alerting
Highlighted

How to create an alert when process appears in multiple IPs?

Path Finder

Say I have a table of processes and IP addresses. I want to make an alert when a certain process was monitored in multiple computers during the last 24 hours. How can I do it?

Very specific question I know, I just didn't know how to phrase it otherwise.

0 Karma
Highlighted

Re: How to create an alert when process appears in multiple IPs?

SplunkTrust
SplunkTrust

@agentsofshield,

Try

your search|fields process,ipaddress|stats dc(ipaddress) as count,values(ipaddress) as ipaddress by process|where count >1

View solution in original post