Find Jobs
Hire Freelancers

splunk query

$8-15 USD / hour

In Progress
Posted over 4 years ago

$8-15 USD / hour

I need to create an alert which will prompt whenever "reason": "LOCKED" appears more than 15% in previous 1 hour. checks to be made every 10m. this should happen only for "operation":"ENROLL" and "operation":"BIND" i have this query which gives me the locked transactions but if I combine it with operation:BIND or ENROLL then I dont get any results even though the application is throwing logs for these. index=abc cf_app_name="stack-overflow" "reason": "LOCKED" AND "operation":"ENROLL" below is the sample log { "id": "c90f975cb368", "source": { "domain": "ABC", "version": "1.0.0", "environment": "stage" }, "namespace": "a.b.c", "resource": "CARD", "operation": "ENROLL", "state": "FAILED", "tags": ["kpi"], "createTime": 156898900, "context": { "correlationId": "0-6093d36" }, "data": { "dpaData": { "dpaId": "1d457051052e71730e71cc5a", "srctId": "526e1bcf-ca6ce85ee9cb", "durbinRights": false }, "dcfData": {}, "srciData": { "srcId": "526e1ca6ce85ee9cb", "name": "mcd }, "appInstanceData": { "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36", "abcdefghijklmnopqrstuvwxyz\"}", "remoteIpAddress": "[login to view URL]", "httpXForwardedFor": "[login to view URL]" }, "authenticationData": { "expiration": false, "authenticationResult": { "reason": "LOCKED" }, "emailVerified": false, "phoneVerified": false }, "consumerData": {}, "error": { "reason": "LOCKED", "message": "Access is denied to the requested resource. The user account has been locked., card locked time: [166898828]", "http-response-code": "400" } } } I just need the query which will give the events where "reason": "LOCKED" under the field error appears along with "operation": "ENROLL"
Project ID: 20816049

About the project

2 proposals
Remote project
Active 5 yrs ago

Looking to make some money?

Benefits of bidding on Freelancer

Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
Awarded to:
User Avatar
HI , I have a good experience in splunk query , dashboards & app development ,i can help you in completing this..............................
$12 USD in 10 days
0.0 (0 reviews)
0.0
0.0
2 freelancers are bidding on average $12 USD/hour for this job
User Avatar
I am a splunk Developer and an admin with 3 years of professional expertise. I am well versed with creation of complex logics using splunk processing language.
$12 USD in 10 days
0.0 (0 reviews)
0.0
0.0

About the client

Flag of INDIA
Bangalore, India
0.0
0
Payment method verified
Member since Jul 10, 2013

Client Verification

Thanks! We’ve emailed you a link to claim your free credit.
Something went wrong while sending your email. Please try again.
Registered Users Total Jobs Posted
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Loading preview
Permission granted for Geolocation.
Your login session has expired and you have been logged out. Please log in again.