Alerting

How to create an alert of a trend Analysis on the same time over a period of time?

srisahitya_v
Communicator

Hello All,

I would like to write a query for an IP which is targeting every day to my system. I would like to make a trend diagram OR alert to showcase these kind of IP's.

But with time chart command, I am unable to fulfill the need.

Example: one IP is scanning my system, every day at 8'O clock in the morning for past 7 days. Then it should trigger an alert.

with time chart I can make the time line with spikes, but not able to trigger alert for above one.

any suggestion?

0 Karma

srisahitya_v
Communicator

@mayurr98:

the query is "index=firewall_log | timechart span=1h count BY IP"
It gives a time line only.

What I need is that an alert should trigger, when a suspicious IP making trend of is accessing my network, "every day same time over a period of time"

Any suggestions?

0 Karma

mayurr98
Super Champion

what is your timechart query?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...