Splunk Search

How to edit my search to only return results that exceed a certain count within a time window?

CREVITCH
Path Finder

I would like to issue the following search, but only get results that exceed a count within a time window. I see how to set an alert to do this, but I just want to search my current stored events. How do I do this in a search?

user=* action=* | stats count by user, action
0 Karma

somesoni2
Revered Legend

Did you try adding a where clause in the end to compare count with your threshold?

Like
your current search ...| where count > yourthreshould

0 Karma

CREVITCH
Path Finder

Thanks. Is there a way to do this for count over a moving time window for stored events? Right now the count is the total over the interval defined by the time range picker. In other words, is there a way to count events by user that exceed a threshold within a moving 5 minute time window over my event history?

0 Karma

CREVITCH
Path Finder

your current search ...| where count > [ search your search to get get threshold for move 5 min window | return $yourthreshold ]

This looks like what I want but not sure of the syntax. I am fine with a fixed thresshold. How do I search for a count of events in a moving 5 minute window that have the string "failed", and output the count when it exceeds a fixed thresshold?

0 Karma

somesoni2
Revered Legend

You can use a subsearch to get the value of yourthreshold to be used. In you subsearch, write your search to get threshold for move 5 min window.

your current search ...| where count > [ search your search to get  get threshold for move 5 min window | return $yourthreshold ]
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...