Alerting

How to calculate the cumulative count of events using relative timeframes?

arthurabreu
Explorer

Hi,

I need to create a search that calculates the cumulative count of a specific event during the weekend.

I have the following query, that will give me the count of distinct hosts that have EventID 6009. These events can happen anytime during the weekend.

index=win_logs sourcetype=System EventID=6009 | stats dc(host) AS TotalHostCount

I've created an alert that will run this search every 2 hours during the weekends (Saturdays AND Sundays) and send an email with the current count, so we can monitor the progress. I did the schedule using cron.

But I am struggling with the right time modifiers to use with the cron schedule... I want to lock my timeframe to look at events between Saturdays 12:00:00AM and Mondays 12:00:00AM

I tried to use earliest=@w6 and it will lock my search to start on Saturdays but when the alert is triggered again on Sunday, it will be considered a new week (w0) and therefore w6 will be a date in the future messing the whole thing up...

Any ideas ?

Thanks!

0 Karma
1 Solution

DalJeanis
Legend

Okay, try something like this...

earliest=-1d@w5+1d 

or

earliest=-1d@w+6d

Try

earliest=-1d@w6

View solution in original post

DalJeanis
Legend

Okay, try something like this...

earliest=-1d@w5+1d 

or

earliest=-1d@w+6d

Try

earliest=-1d@w6

arthurabreu
Explorer

Hi DalJeanis.

Thanks for your suggestion but as I mentioned on my original question, I have to lock in a specific timeframe (Saturdays 12:00:00AM and Mondays 12:00:00AM) and still be able to execute the query every 2 hours during the weekend.
earliest=-1d@w6 will work fine for Sunday, but if I run the query it on Saturday it will give me results from Friday, which is outside the desired timeframe.

0 Karma

DalJeanis
Legend

@arthurabreu - updated the answer, try the new code.

0 Karma

arthurabreu
Explorer

thank you, that did the trick! 🙂

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...