Splunk Search

Event Correlation

lsipps
New Member

Hey splunkers,

i am stucked with the following Request:

Generate an Alarm, i suppose with an scheduled search, that fires if eventtype xy occurs. In addition if within x minutes, after this Alarm, an log event occurs with an Parameter from the scheduled search, then trigger an Shell Script.

Hopefully you get what i am meaning....otherwise i´ll have to explenate my issue a little bit more....

Have a nice weekend!

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

0 Karma

lsipps
New Member

Localize sounds not bad, but it is not the solution of this particular Requirement. An Example:
I have got a scheduled search Named "IDS Alarm". If the number of Events for this scheduled search is greater 0 a Shell Script is triggered - no big Thing.
But: if as result within x minutes after the Script is triggered there is a Log entry with an entry from the scheduled Search Result (in case an IP Address) I want to fire another Script. How can I realize this Construct?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...