Splunk Search

complex stats to trigger on count of events

dm2
Explorer

I have this rule, I need it to trigger when results / count of events is greater than 4 but the "Trigger Condition" did not work.
Is there something I can add to the query ? 

dm2_0-1709121026938.png

dm2_1-1709121061997.png

 

Labels (1)
0 Karma

dm2
Explorer

I saying that the rule needs to trigger when events > 4, and the 'Trigger Condition' did not work.

This is the rule that triggered (triggered on one event):

dm2_0-1709127715520.png

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

ok something is not clear. 

the trigger condition is results count greater than 4, then trigger/run the trigger conditions. 

1) do you say that when the results are greater than 4, but still the trigger did not work. 

2) on your latest reply, you got only one result, but the trigger condition ran successfully ya?

Can you pls attach the trigger conditions screenshot pls. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm2,

please, share your search in text mode, otherwise it's more difficoult to help you.

You can insert the text using the "Insert/Edit code sample" button.

Ciao.

Giuseppe

0 Karma

dm2
Explorer
| stats count dc("File Name") as "File Name Count" first(_time) as _time, values(host) as host, values("File Type") as "File Type", values(Policy) as Policy, values(SHA256) as SHA256, values("Block Reason") as "Block Reason", values(Blocked) as Blocked by "File Name"
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @dm2 .. the SPL looks good and working fine also(as per the image). 

the trigger condition says the result greater than 4 and the image shows result 1. so the trigger condition was not triggered. 

are you saying that, when the result is greater than 4 also the trigger condition not triggering?

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...