Splunk Search

Correlation alert with multiple events

LIP
Loves-to-Learn

Hi,

I want to create a Correlation alert that will trigger and collect all the events from the same IP within a certain time. I try to "group by", but, not work

 

THX

 

 

0 Karma

nmohammed
Builder

@LIP 

can you share sample events and the search you're trying to run ?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...