Splunk Search

Correlation alert with multiple events



I want to create a Correlation alert that will trigger and collect all the events from the same IP within a certain time. I try to "group by", but, not work





Labels (1)
0 Karma



can you share sample events and the search you're trying to run ?

0 Karma
Get Updates on the Splunk Community!

Testing out the OpenTelemetry Collector With raw Data

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...