Alerting

Can the date_hour, date_minute and date_second fields be used in realtime searches?

krdo
Communicator

When I run the following search using All time (real-time) no results are returned;

* AND (date_hour!=13 OR date_minute<50 OR date_minute>55)

Why is this? When I change the time range to 30 second window the expected results are returned. I wanted to create a real-time alert based on the search but it never triggers.

0 Karma

krdo
Communicator

I found a workaround:

* | search (date_hour!=13 OR date_minute<50 OR date_minute>55)

But to be honest, I have no idea why this works...

0 Karma

markthompson
Builder

You say when you set it to a 30-sec window it works, but what window do you want to use?
Also, why are you searching for just *?

0 Karma

krdo
Communicator

* will be replaced by the actual search parameters, I just wanted to make sure I get lots of events to check whether my time window filter works correctly. I started with all filters and found out that no results are returned as soon as I add the time window filter. The alert will be using a sliding 5 minute window with additional search parameters.

0 Karma

markthompson
Builder

It might be that you're getting too many results. Is this a table? Or is it a graph?

0 Karma

krdo
Communicator

I just run the search above and use the events viewer. The 30 seconds window returns around ~70 results.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...