Hi,
I need some analytics result in Splunk but i couldn't achieve. Here what i need.
1) Which EventIDs is repeated in which hostnames? I need this count based. EventID, Hostname and Count
2) Which EventIDs is used in which alerts (correleation searches and saved searches)? EventID, Alert Name
3) Which EventIDs triggered which alerts? EventID, Alert Name and count
I tried below search for 2nd question but didn't work.
P.S: In my environment we parsed EventID as EventCode
| rest /services/saved/searches
| search is_scheduled=1 OR alert_type=1
| table title, actions
| mvexpand actions
| rex field=actions ".*EventCode=(?<EventCode>\d+).*"
| stats count by EventCode, title
Please help me..
I found 1. item with this search.
index=wineventlog
| stats count by EventCode, host
| where count > 1
| sort -count
| table EventCode, host, count
I need 2 and 3rd items