Using the _internal index, here's the best approximation I can give you (my server name is "Voyager-2"):
index=_internal | timechart span=1s count by host | search Voyager-2>10
So in your case, something like this should do the trick:
host="abc0" DN= NOT DN="45643232" NOT DN="53222455" | timechart span=1s count by host
Then you create an alert based on your saved search that will trigger if the number of results is greater than 10.
Hope this helps 🙂
host="abc0" DN= NOT DN="45643232" NOT DN="53222455" | timechart span=1s count by DN
This comes closer than I was, but this will alert if the occurence of DN is higher than 10 per second.
DN can hold many values, I need it to alert when a distinct value occurs more than 10 times per second.
Thanks for helping though