Splunk Search

How can I search for the alerts usecase?

AL3Z
Builder


Hi, Need a search for the below usecase 

Search for alert_type=ufa and alert_name="  suspicious  Downloads"
Please include all  domains present in the domains.csv  from  this search 

We are looking for users that trigger the one above AND this one:

Search for alert_type=ufa and alert_name=" suspicious  uploads"
Please exclude all domains present in the domains.csv  from this search
Thanks...

Thanks...

Labels (4)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @AL3Z,

You didn't provide field names in the events and lookup file. I assume domains.csv is a lookup file in Splunk. Please try below sample; I assumed your event and csv file has a field named "domain"

alert_type=ufa and alert_name="suspicious uploads" NOT [inputlookup domains.csv | fields domain | format]

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...