I am trying to figure a way to create a rule that notifies me of webpages that been hit more than a few times per seconds?


this rule would help determine if a DDOS attempt is or isn't occurring.

Tags (1)
0 Karma


Something like this?

search for web page hits | bin span=1m _time | stats count by _time uri | where count > 120

That'd give you a list of URIs that had an average of over two hits per second along with the minute in which that occurred.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!