Splunk Search

Event Correlation

lsipps
New Member

Hey splunkers,

i am stucked with the following Request:

Generate an Alarm, i suppose with an scheduled search, that fires if eventtype xy occurs. In addition if within x minutes, after this Alarm, an log event occurs with an Parameter from the scheduled search, then trigger an Shell Script.

Hopefully you get what i am meaning....otherwise i´ll have to explenate my issue a little bit more....

Have a nice weekend!

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

0 Karma

lsipps
New Member

Localize sounds not bad, but it is not the solution of this particular Requirement. An Example:
I have got a scheduled search Named "IDS Alarm". If the number of Events for this scheduled search is greater 0 a Shell Script is triggered - no big Thing.
But: if as result within x minutes after the Script is triggered there is a Log entry with an entry from the scheduled Search Result (in case an IP Address) I want to fire another Script. How can I realize this Construct?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...