Alerting

How to edit my search to alert me on heavy frequency change on Netflow?

nickbijmoer
Path Finder

Hello guys,

I want to generate an alert when my netflow count is something like 10% above the usual average count.
I got something like this but i don't know how to go further 😞

sourcetype="cisco:asa"  earliest=-7d@d latest=@d   | stats count by date_mday  | eventstats avg(count)

can someone help me?

Greetings,

Nick

0 Karma

somesoni2
Revered Legend

Give this a try (assuming you want to compare today's count with last 7 day's average count. If not adjust the relative_time value in eval period ).

sourcetype="cisco:asa" earliest=-7d@d latest=now | timechart span=1d count | eval period=if(_time>=relative_time(now(),"@d"),"today","last7days") | eval temp=1
| stats avg(count) as avgcount over temp by period | fields - temp
| where today>1.1*last7days
0 Karma

nickbijmoer
Path Finder

I get the error: Error in 'stats' command: The argument 'over' is invalid.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...