<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security-violation error in Security</title>
    <link>https://community.splunk.com/t5/Security/security-violation-error/m-p/251472#M14915</link>
    <description>&lt;P&gt;Yes, it is possible.  If you can search for it, you can alert on it.  Once you've produced a search that finds the event(s) of interest, schedule it to run at some interval - every 15 minutes, for example.  Then choose an alert trigger.  I've found &lt;CODE&gt;if number of events&lt;/CODE&gt; &lt;CODE&gt;is equal to&lt;/CODE&gt; &lt;CODE&gt;0&lt;/CODE&gt; works best for my searches.  Mark the &lt;CODE&gt;Send email&lt;/CODE&gt; box and fill in the addresses to which to send the alert.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2016 13:26:52 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2016-08-26T13:26:52Z</dc:date>
    <item>
      <title>security-violation error</title>
      <link>https://community.splunk.com/t5/Security/security-violation-error/m-p/251471#M14914</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;is there anyway i can genrate alert and send mail from splunk .&lt;BR /&gt;
for eg:- if there is an security-violation error on a particular switch like err-disable state if someone tried to connect a switch or router on a access port.&lt;/P&gt;

&lt;P&gt;or &lt;/P&gt;

&lt;P&gt;if a stack one of the switch went down splunk should send me an alert via email to my network team.&lt;/P&gt;

&lt;P&gt;is it possible ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 12:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/security-violation-error/m-p/251471#M14914</guid>
      <dc:creator>vineeth10</dc:creator>
      <dc:date>2016-08-26T12:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: security-violation error</title>
      <link>https://community.splunk.com/t5/Security/security-violation-error/m-p/251472#M14915</link>
      <description>&lt;P&gt;Yes, it is possible.  If you can search for it, you can alert on it.  Once you've produced a search that finds the event(s) of interest, schedule it to run at some interval - every 15 minutes, for example.  Then choose an alert trigger.  I've found &lt;CODE&gt;if number of events&lt;/CODE&gt; &lt;CODE&gt;is equal to&lt;/CODE&gt; &lt;CODE&gt;0&lt;/CODE&gt; works best for my searches.  Mark the &lt;CODE&gt;Send email&lt;/CODE&gt; box and fill in the addresses to which to send the alert.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 13:26:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/security-violation-error/m-p/251472#M14915</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2016-08-26T13:26:52Z</dc:date>
    </item>
  </channel>
</rss>

