Let say I have a few searches :
alert1
search | eval etc | stats count by field1, field2, etc
alert2
search | eval etc | stats count by field1, field2, etc
alert3
search | eval etc | stats count by field1, field2, etc
Now i want to make search for top alerts, though i cant make eventypes, whats the most handy way to get here ?
Oke thanks, I am aware it isnt easy, this is just a general question, and the 3 searches are an example to decribe the functional fundamentals.
Bottemline is I have seperate searches which are running in notification if there is a (siem) hit, those are combis of eval, subsearches, lookups etc. So just wondered if i can run a top just like evettypes top.
On the dashboards i have per search, postprocesses, with linkswitches, intentions to drills etc etc..
I will diginto this later but appreantly its more complex then i was thinking ( just though i could group "search" results and simple count them....
A few approaches...
Find out why you can't define eventttypes. Talk to your Splunk admin and have the eventttypes added for you, or ask for permissions to do it yourself.
Use 'OR' conditions in your search string, and group by some field other than eventtype
. signature
or EventCode
might be a good choice, depending on your alert conditions.
Run your existing searches, but don't send email alerts. Instead, enable summary indexing. Run a separate search against the summary index for alerting.
Run your existing searches, but don't send email alerts. If all you care about is the result count, you can search against index=internal SavedSplunker
to find the number of results that matched. Then use savedsearch_name
like you would eventtype
.
Use |append
to run your three searches, and create your equivlalent to the eventtype field for each alert type using eval
. Then pipe the whole mess into top
or stats
.
Stange that this one is devoted...the search hit is an alert and differs per alert (fi external lookup for fields which are allowed, or users who are logged into a system with non allowed name etc etc...
So if there is a search hit then its an alert....now i want a consolidated overview instread of a bunch of loose rangemap values.
What defines an alert? What defines alert count?