Splunk Search

Count of specific event

havatz
Explorer

HI all,

I have this rule:

"Unapproved Port Activity Detected" - I know this rule creates many alerts, how can i find the daily count of this specific event? and what is trigger?

 

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

You can find details in index=notable

to find number of notables triggered for that correlation rule use below query.

index=notable source=*Unapproved Port Activity Detected
| timechart span=1d count

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...