how to create report/alert with repeating same ip address

New Member

I have a threatid from firewall with IP address information. and want to ask is it possible to create report/alert for the repeating same ip address after 7 days without manually input the ip address?

Tags (1)
0 Karma


You could try something like this and alert if count>0

... earliest=-7d@d | stats count as occurrences by ip | where occurrences>(enter your threshold number here)
0 Karma


This should get you started.

index=foo threatid=bar | bin span=7d _time | stats count by ipaddress | where count > 1
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...