Splunk Search

how can I get a deviation from a specific IP?

christianubeda
Path Finder

Good afternoon,

I have this query to get global deviations in the number of connections.

index=cisco_asa sourcetype="cisco:asa" Cisco_ASA_action=allowed earliest=-1w
| timechart count span=1d
| where strftime(_time, "%A") == strftime(now(),"%A")
| timewrap w
| rename "* ago" as * | eval avg=Total/3.0 | rename latest_week as Today 1week_before as Lastday _time as Date | eval ChangePercent = (Today - Lastday) / 100 | convert timeformat="%m/%d/%Y %H:%M:%S" ctime(Date) | where ChangePercent > 0.20

if I wanted to detect the deviation per server as I could do?

Thank you

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...