Splunk Enterprise Security

Time taken to Resolve Incident

Explorer

I need to calculate average time take to resolve different incidents in splunk. If anybody have query for same??

0 Karma
1 Solution

Explorer

In the end, I have created a solution for it myself. https://splunkbase.splunk.com/app/4591/

View solution in original post

0 Karma

Explorer

In the end, I have created a solution for it myself. https://splunkbase.splunk.com/app/4591/

View solution in original post

0 Karma

New Member

I have the same requirement.
I need to calculate the average time for all the notables to get resolved over a 30 day period.
Can anyone help me with the splunk query regarding same?

Regards
Prashant

0 Karma

Path Finder

Amit,

I couldn't get the question properly. Could you please explain in precise.

Saikrishna

0 Karma

Explorer

We have different notable search and have alerts to trigger for same. I need to have query which shows when incident status changes to "in progress" and when to "resolve" and average ( consider for monthly ) time taken to resolve it.

0 Karma