Splunk Enterprise

How do I Identify anomalous changes in event counts across critical hosts and sources in Splunk & ES?

SamHTexas
Builder

I have a large Splunk & ES environment and use DMC daily. Are there a series of SPL that would help me perform such tasks. Thank u in advance.

Labels (1)
Tags (1)
0 Karma

inventsekar
Super Champion

Hi @SamHTexas .. 

critical hosts and sources - may we know this list is a small one with few hosts and sources or a large list?

for example, if you got only less than 5 / 10 hosts, we can use simple SPL query.. 

if the list is big, then

1) you should create a CSV file  -  host or source - number of logs today - date of today

2) then create alert on that CSV file and create email alerts

 

the basic idea: just the reverse of idea of host stops sending logs:

https://www.splunk.com/en_us/blog/tips-and-tricks/how-to-determine-when-a-host-stops-sending-logs-to...

(if a host sent more than 1million logs in last 24 hrs, create an email notification)

 

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!