Videos

  • Add Videos
  • View All

Latest Activity

Profile IconWilliam S and Please... Dee Esssss :-) joined splunkninja
1 hour ago
Amine Recoba is now a member of splunkninja
yesterday
Michael Wilde replied to Nikita's discussion Count failures and success via transaction
"How are these transactions linked together... by a field called "ID"?  If so.. just build them with the field ID, and then use one of the MV commands to extract a field with success or failure in it.   Paste some samples and…"
Friday
Linus Myrefelt updated their profile
May 22
Marie updated their profile
May 21
Marie is now a member of splunkninja
May 21
Profile IconJitter and matthew arguin joined splunkninja
May 18
Profile IconMatthew Carter and Nikita joined splunkninja
May 17
Event aggregation

Is there any way to create event aggregation in splunk ?
what happened is I got license violations do to Windows security event
log  that repeated itself over 600,000 times in 2 hours

is there a way that I can "teach" splunk to alert when such a think
happen and ignore or drop the excessive event

splunk version is 4.0.10  .and for now I have an alert on license
violation , after the alert I searched for the 'Top
five sourcetypes (by total KB indexed) in the last 24 hours' (
splunkninja.com/profiles/blogs/getting-more-intelligence-on)
and found the problematic event , but I only did this after the license violation
occurred


any ideas ?

Views: 15

Reply to This

© 2012   Created by Michael Wilde.

Badges  |  Report an Issue  |  Terms of Service