Splunk Enterprise

How do I Identify anomalous changes in event counts across critical hosts and sources in Splunk & ES?

SamHTexas
Builder

I have a large Splunk & ES environment and use DMC daily. Are there a series of SPL that would help me perform such tasks. Thank u in advance.

Labels (1)
Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @SamHTexas .. 

critical hosts and sources - may we know this list is a small one with few hosts and sources or a large list?

for example, if you got only less than 5 / 10 hosts, we can use simple SPL query.. 

if the list is big, then

1) you should create a CSV file  -  host or source - number of logs today - date of today

2) then create alert on that CSV file and create email alerts

 

the basic idea: just the reverse of idea of host stops sending logs:

https://www.splunk.com/en_us/blog/tips-and-tricks/how-to-determine-when-a-host-stops-sending-logs-to...

(if a host sent more than 1million logs in last 24 hrs, create an email notification)

 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...