Splunk Enterprise Security

Top alerts fires

saotaigiri
Path Finder

Please I am looking for a query to search for the top alerts that fired within 2 weeks (or within a time frame).

I am also looking for a query to show anomalies within a time frame

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Start with this query.

| rest/servicesNS/-/-/alerts/fired_alerts| search NOT title="-"

Your second question is far too broad to attempt to answer.  Please post a new question with more specifics.  What kind of data?  What is considered an anomaly?  What time frame? 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...