Hi,
Could anyone over here able to write an spl query for usecase in splunk ES like when single user triggers alert say other than dlp in between 2 hours of time more than 3 times,how to make a count for alert_name
not for generic events, how to write this use case spl query using eval ?