Splunk Search

Event Correlation

lsipps
New Member

Hey splunkers,

i am stucked with the following Request:

Generate an Alarm, i suppose with an scheduled search, that fires if eventtype xy occurs. In addition if within x minutes, after this Alarm, an log event occurs with an Parameter from the scheduled search, then trigger an Shell Script.

Hopefully you get what i am meaning....otherwise i´ll have to explenate my issue a little bit more....

Have a nice weekend!

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

0 Karma

lsipps
New Member

Localize sounds not bad, but it is not the solution of this particular Requirement. An Example:
I have got a scheduled search Named "IDS Alarm". If the number of Events for this scheduled search is greater 0 a Shell Script is triggered - no big Thing.
But: if as result within x minutes after the Script is triggered there is a Log entry with an entry from the scheduled Search Result (in case an IP Address) I want to fire another Script. How can I realize this Construct?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...