Splunk Search

Detecting suspicious activity in search * See examples.

omgwut56k
Path Finder

I need to be able to detect this pattern of events, in a series of events where the TERMINAL number is increasing by 1 and eventually has a status of 'S', in other words, I need to be detect the event(s) that have a status of 'S' where the preceding 5 events were increasing by 1 and had a status of 'F'.

Thank you

_time TERMINAL DLDTYPE STATUS

2015-02-10T15:29:21.000-0500 1759512 U F
2015-02-10T15:29:31.000-0500 1759513 U F
2015-02-10T15:29:42.000-0500 1759514 U F
2015-02-10T15:30:17.000-0500 1759515 F S
2015-02-10T15:32:20.000-0500 1759516 F S

2015-02-10T15:33:31.000-0500 1759517 U F
2015-02-10T15:34:42.000-0500 1759518 U F

Tags (3)
0 Karma
1 Solution

omgwut56k
Path Finder

This seems to be working so far

| delta TERMID AS delta | table _time TERMINAL delta STATUS MESSAGE | search delta="-1" STATUS=S

View solution in original post

0 Karma

omgwut56k
Path Finder

This seems to be working so far

| delta TERMID AS delta | table _time TERMINAL delta STATUS MESSAGE | search delta="-1" STATUS=S

0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...