<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic create EXTRACTION in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531440#M10001</link>
    <description>&lt;P&gt;Good day, I would like to create an alert for the below error, can i get a regex for the higlighted part&amp;nbsp; and how would i go about creating the alert, or should I just look out for the event and set to trigger whenever its &amp;gt; 0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="t"&gt;2020-11-14&lt;/SPAN&gt; &lt;SPAN class="t"&gt;23:04:24&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;http-nio-127.0.0.1-7080-exec-7&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;LdapHealthChecker&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;loading&lt;/SPAN&gt; &lt;SPAN class="t"&gt;the&lt;/SPAN&gt; &lt;SPAN class="t"&gt;user&lt;/SPAN&gt; &lt;SPAN class="t"&gt;groups&lt;/SPAN&gt; &lt;SPAN class="t"&gt;from&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LDAP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Please&lt;/SPAN&gt; &lt;SPAN class="t"&gt;check&lt;/SPAN&gt; &lt;SPAN class="t"&gt;the&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ldap.server.url&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ldap.bind.dn&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ldap.bind.password&lt;/SPAN&gt; &lt;SPAN class="t"&gt;secure&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;properties.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Refer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Manage&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Configuration&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Properties&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Guide&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;org.springframework.ldap.AuthenticationException:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;LDAP:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;80090308:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LdapErr:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DSID-0C090453&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;comment:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AcceptSecurityContext&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;52e&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;v3839\x00&lt;/SPAN&gt;&lt;SPAN&gt;]; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;nested&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exception&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;javax.naming.AuthenticationException:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;LDAP:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;80090308:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LdapErr:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DSID-0C090453&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;comment:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AcceptSecurityContext&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;52e&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;v3839\x00&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 06:18:43 GMT</pubDate>
    <dc:creator>sphiwee</dc:creator>
    <dc:date>2020-12-01T06:18:43Z</dc:date>
    <item>
      <title>create EXTRACTION</title>
      <link>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531440#M10001</link>
      <description>&lt;P&gt;Good day, I would like to create an alert for the below error, can i get a regex for the higlighted part&amp;nbsp; and how would i go about creating the alert, or should I just look out for the event and set to trigger whenever its &amp;gt; 0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="t"&gt;2020-11-14&lt;/SPAN&gt; &lt;SPAN class="t"&gt;23:04:24&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;http-nio-127.0.0.1-7080-exec-7&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;LdapHealthChecker&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;loading&lt;/SPAN&gt; &lt;SPAN class="t"&gt;the&lt;/SPAN&gt; &lt;SPAN class="t"&gt;user&lt;/SPAN&gt; &lt;SPAN class="t"&gt;groups&lt;/SPAN&gt; &lt;SPAN class="t"&gt;from&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LDAP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Please&lt;/SPAN&gt; &lt;SPAN class="t"&gt;check&lt;/SPAN&gt; &lt;SPAN class="t"&gt;the&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ldap.server.url&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ldap.bind.dn&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ldap.bind.password&lt;/SPAN&gt; &lt;SPAN class="t"&gt;secure&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;properties.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Refer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Manage&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Configuration&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Properties&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Guide&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;org.springframework.ldap.AuthenticationException:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;LDAP:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;80090308:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LdapErr:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DSID-0C090453&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;comment:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AcceptSecurityContext&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;52e&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;v3839\x00&lt;/SPAN&gt;&lt;SPAN&gt;]; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;nested&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exception&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;javax.naming.AuthenticationException:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;LDAP:&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;80090308:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LdapErr:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DSID-0C090453&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;comment:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;AcceptSecurityContext&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;52e&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;v3839\x00&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 06:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531440#M10001</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-12-01T06:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: create EXTRACTION</title>
      <link>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531442#M10002</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first, if you have to search the string "&lt;STRONG&gt;&lt;SPAN class="t"&gt;LDAP:&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN class="t"&gt;code&lt;/SPAN&gt;&lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;" you don't need a regex but a simple text search.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Then you have to manage the threeshold and you can do this in two ways:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;in the same search,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;in the number of occurrencies.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;In the first case, you can run a search like this:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your_search "LDAP: error code 49"
| stats count
| where count&amp;gt;0&lt;/LI-CODE&gt;&lt;P&gt;where 0 is the threeshold that obviously will has the value you need.&lt;/P&gt;&lt;P&gt;Otherwise, you can run only the search (without stats and where) and manage the threeshold in the number occurrencies in the alert definition.&lt;/P&gt;&lt;P&gt;I usually prefer the first solution, but they are the same thing.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 07:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531442#M10002</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-01T07:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: create EXTRACTION</title>
      <link>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531461#M10003</link>
      <description>&lt;P&gt;I want to have a message on the alert such as "&lt;STRONG&gt;Error code alert on host: ........&lt;/STRONG&gt;"&lt;BR /&gt;&lt;BR /&gt;The way you're doing it is this achievable? and how?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 08:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531461#M10003</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-12-01T08:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: create EXTRACTION</title>
      <link>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531491#M10004</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to modify the search adding the host information:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your_search "LDAP: error code 49"
| stats count BY host
| where count&amp;gt;0&lt;/LI-CODE&gt;&lt;P&gt;then add the info following the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Alert/EmailNotificationTokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Alert/EmailNotificationTokens&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;STRONG&gt;Error code alert on host: ........&lt;/STRONG&gt;&lt;SPAN&gt;$result.&lt;/SPAN&gt;&lt;I&gt;fieldname&lt;/I&gt;&lt;SPAN&gt;$&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 11:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/create-EXTRACTION/m-p/531491#M10004</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-01T11:12:38Z</dc:date>
    </item>
  </channel>
</rss>

