- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Top alerts fires
saotaigiri
Path Finder
09-10-2020
10:54 AM
Please I am looking for a query to search for the top alerts that fired within 2 weeks (or within a time frame).
I am also looking for a query to show anomalies within a time frame
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-10-2020
12:24 PM
Start with this query.
| rest/servicesNS/-/-/alerts/fired_alerts| search NOT title="-"
Your second question is far too broad to attempt to answer. Please post a new question with more specifics. What kind of data? What is considered an anomaly? What time frame?
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
