Splunk Search

Only execute if greater than or equal to x mins

hl
Path Finder

Hello looking for way to create an alert based off the difference between times and only execute if the time is greater than or equal to x mins. 

 

Code: 

index=net* sourcetype=pan:* 
action="blocked" OR action="failure"
|stats count min(_time) as firstTime 
max(_time) as lastTime
by src_ip,dest,dest_port,rule,tag,log_subtype,transport |where count >= 10 
|eval diff=lastTime-firstTime
```|eval diff=strftime(diff, "%d %H:%M:%S") ```
|eval diff=strftime(diff, "%M:%S") 
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`

 Regards, 

 

Labels (1)
0 Karma

hl
Path Finder

Actually I think I figured this out!

 

index=netfw sourcetype=pan:* 
action="blocked" OR action="failure"
|stats count min(_time) as firstTime max(_time) as lastTime by src_ip |where count >= 10
|eval diff=floor((lastTime-firstTime)) 
|eval "Difference in Mins" = floor((diff / 60)) 
|eval SortbyMins="Difference in Mins"
|fields - diff,SortbyMins
|sort - SortbyMins

| `security_content_ctime(firstTime)` 
| `security_content_ctime(lastTime)`
0 Karma

hl
Path Finder

Created this instead, 

index=net* sourcetype=pan:* 
action="blocked" OR action="failure"
|stats count min(_time) as firstTime max(_time) as lastTime by src_ip |where count >= 10
|eval diff=toString(lastTime-firstTime, "duration")
| `security_content_ctime(firstTime)` 
| `security_content_ctime(lastTime)`

 but still trying to figure out how to only show results if greater than x mins. ?  

0 Karma

hl
Path Finder

I just wanna make variable and assign it but I know I can't do that and you can't create boolean on an eval 

 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...