Splunk Search

How to write SPL for DLP alert use case using eval in Splunk ES?

AL3Z
Builder

Hi,
Could anyone over here  able to write an spl query for usecase in splunk ES like when single user triggers alert say other than dlp  in between 2 hours of time more than 3 times,how to make  a count for alert_name
not for generic events, how to write this use case spl query using eval ?


Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...