Splunk Search

How to edit my search to only return results that exceed a certain count within a time window?

CREVITCH
Path Finder

I would like to issue the following search, but only get results that exceed a count within a time window. I see how to set an alert to do this, but I just want to search my current stored events. How do I do this in a search?

user=* action=* | stats count by user, action
0 Karma

somesoni2
Revered Legend

Did you try adding a where clause in the end to compare count with your threshold?

Like
your current search ...| where count > yourthreshould

0 Karma

CREVITCH
Path Finder

Thanks. Is there a way to do this for count over a moving time window for stored events? Right now the count is the total over the interval defined by the time range picker. In other words, is there a way to count events by user that exceed a threshold within a moving 5 minute time window over my event history?

0 Karma

CREVITCH
Path Finder

your current search ...| where count > [ search your search to get get threshold for move 5 min window | return $yourthreshold ]

This looks like what I want but not sure of the syntax. I am fine with a fixed thresshold. How do I search for a count of events in a moving 5 minute window that have the string "failed", and output the count when it exceeds a fixed thresshold?

0 Karma

somesoni2
Revered Legend

You can use a subsearch to get the value of yourthreshold to be used. In you subsearch, write your search to get threshold for move 5 min window.

your current search ...| where count > [ search your search to get  get threshold for move 5 min window | return $yourthreshold ]
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...