Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to collect log within 1 hours from file log rotate

$
0
0
Dear all I have file log access /var/log/secure . Use log rotate ( setting daily) I need collect log login fail 3 times on 1 IP within 1 hour from file log /var/log/secure. I use query: > source="/var/log/secure" sourcetype=linux_secure process=sshd "password for" NOT pam_unix NOT Accepted earliest=-24h latest=now | rex field=_raw "(?Accepted|Failed) password for (?\w+) from (?[0-9A-Fa-f:\.]+)" | stats count by ipaddr | where count >=3 I need support collect log with 1 hours Please support me

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>