Splunk Search

Event Correlation

lsipps
New Member

Hey splunkers,

i am stucked with the following Request:

Generate an Alarm, i suppose with an scheduled search, that fires if eventtype xy occurs. In addition if within x minutes, after this Alarm, an log event occurs with an Parameter from the scheduled search, then trigger an Shell Script.

Hopefully you get what i am meaning....otherwise i´ll have to explenate my issue a little bit more....

Have a nice weekend!

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

0 Karma

lsipps
New Member

Localize sounds not bad, but it is not the solution of this particular Requirement. An Example:
I have got a scheduled search Named "IDS Alarm". If the number of Events for this scheduled search is greater 0 a Shell Script is triggered - no big Thing.
But: if as result within x minutes after the Script is triggered there is a Log entry with an entry from the scheduled Search Result (in case an IP Address) I want to fire another Script. How can I realize this Construct?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...