Splunk Search

Event Correlation

lsipps
New Member

Hey splunkers,

i am stucked with the following Request:

Generate an Alarm, i suppose with an scheduled search, that fires if eventtype xy occurs. In addition if within x minutes, after this Alarm, an log event occurs with an Parameter from the scheduled search, then trigger an Shell Script.

Hopefully you get what i am meaning....otherwise i´ll have to explenate my issue a little bit more....

Have a nice weekend!

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

The first one is easy. You can schedule a search for eventtype=xy and then send an email if that happens. The second one you might need to explain a bit more on, but it sounds like you should be able to do something with localize. Check out the following link, and if that doesn't get you where you need to be, can you give an example of the initial event and the follow-up event?

http://answers.splunk.com/questions/2602/can-splunk-filter-match-events-and-bring-back-neighbouring-...

0 Karma

lsipps
New Member

Localize sounds not bad, but it is not the solution of this particular Requirement. An Example:
I have got a scheduled search Named "IDS Alarm". If the number of Events for this scheduled search is greater 0 a Shell Script is triggered - no big Thing.
But: if as result within x minutes after the Script is triggered there is a Log entry with an entry from the scheduled Search Result (in case an IP Address) I want to fire another Script. How can I realize this Construct?

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...