Deployment Architecture

More than 100 “EventID=8306 sourcetype="xyz"” in 15 minutes on an individual host base

mvishal
Explorer

i want an alert setup in splunk for 100 occurrence of event id 8306 per host for sourcetype "xyz" in 15 minutes..

Can anyone suggest ??

Tags (2)
0 Karma

sc0tt
Builder

What about something like sourcetype="xyz" EventID=8306 | stats count by host | where count > 100 then schedule it to run every 15 minutes for the previous 15 minutes, start time = -15m@m finish time = @m?

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...