New Keyword App

One of the most common requests I get from new customers is that they want to centrally collect all their machine generated time series data and search for a keyword like error or RuntimeException. Obviously Splunk can do this. Then, the next set of questions concern things like give me the top hosts or applications producing this keyword, show me a baseline of last week vs this week for this keyword, show me a slope line on the trend for this or any keyword(s), find outliers that go beyond the average occurrences for the keyword and then try to predict what may happen in the future.

To answer these questions and then some, I’ve created an app template that you can download from Splunkbase and simply install the Keyword App. The app has no inputs as it uses your own indexed data. You can modify the default indexes for the role that uses the app in Manager to include indexes beyond main. Usually, what I do next in these blog entries is describe how to use the app. However, in this case, a picture is worth a thousand words. Rather than continue to entertain you with my prose, I’ll simply embed the the self explanatory dashboards here.

Top Host, Sourcetype, Source

Top Host, Sourcetype, and Source for Keyword

Comparing Present Count vs. Past Count

Slope for Trend

Find Outliers

Predict Future Counts (Recession Predict is Jack Coate’s idea)

There’s a Donut Chart (Ron Naken’s Module) that allows you to split your list of keywords by top 10 host, source, or sourcetypes and see the distribution of events.

Split Keyword(s) Distribution by Top 10 Hosts, Source, or Sourcetype

Here are rare events based on your filter:

Rare

Finally, here are rare events based on punctuation.

Punct

Conclusion

Hopefully, this template will satisfy all your needs out of the box. If you need to modify the searches, make a copy of the app’s default/data/ui/views/<dashboard>.xml file and put it into the app’s local/data/ui/views/<dashboard>.xml file and edit your local copy. I’m hoping this app will save you some time from configuring these common tasks.

Related Articles

I Azure You, This Will Be Useful
Security
3 Minute Read

I Azure You, This Will Be Useful

This blog post describes how to use Azure Active directory for basic hunting and discovery
What Keeps the CISO Awake at Night? Four Dreaded Security Headlines
Security
2 Minute Read

What Keeps the CISO Awake at Night? Four Dreaded Security Headlines

Would your organization's security team be prepared if these headlines appear in tomorrow's news?
Domestic Intelligence Service of the Federal Republic of Germany Warns About Cyber Attacks
Security
3 Minute Read

Domestic Intelligence Service of the Federal Republic of Germany Warns About Cyber Attacks

What's happened, how to investigate if you've been affected and what you should do next.
Knowledge is Power: Guidance from ICO and NCSC on GDPR Security Outcomes
Security
2 Minute Read

Knowledge is Power: Guidance from ICO and NCSC on GDPR Security Outcomes

The GDPR learnings are ongoing - are you keeping up?
Boss of the SOC (BOTS) Investigation Workshop for Splunk
Security
3 Minute Read

Boss of the SOC (BOTS) Investigation Workshop for Splunk

You've played BOTS with Splunk, now learn the how it all happened? This post discusses a new tutorial app that you can run on the BOTS v1 dataset to learn more about BOTS and have an educational workshop at home (or office)
Boss of the SOC Scoring Server, Questions and Answers, and Dataset! Open-Sourced and Ready for Download
Security
2 Minute Read

Boss of the SOC Scoring Server, Questions and Answers, and Dataset! Open-Sourced and Ready for Download

We have open-sourced the Boss of the SOC dataset (ver1.0) and BOT(S|N) scoring server. They can be used to run your own CTF, perform research, or train your internal users!
Strengthen Your SIEM And Be Ready For The GDPR
Security
1 Minute Read

Strengthen Your SIEM And Be Ready For The GDPR

When facing the GDPR, your SIEM solution can be a great support for your organisation's compliance strategy, but if not strengthened - it can also be your downfall.
Use Investigation Workbench to Reduce Time to Contain and Time to Remediate
Security
2 Minute Read

Use Investigation Workbench to Reduce Time to Contain and Time to Remediate

The latest version of Splunk Enterprise Security v 5.0 introduces Investigation Workbench, which streamlines investigations and accelerates incident response
Detecting Typosquatting, Phishing, and Corporate Espionage with Enterprise Security Content Update
Security
3 Minute Read

Detecting Typosquatting, Phishing, and Corporate Espionage with Enterprise Security Content Update

Splunk’s Enterprise Security Content Update (ESCU) app can provide you with early warnings and situational awareness—powerful elements of an effective defense against adversaries