<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alerting using inputlookup in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535796#M10113</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Hi all, im new in splunk, i was wondering if you can help me. This is&amp;nbsp; the scenario, im using inputlookup. I have csv&amp;nbsp; file with 2 fields field1 is original ip then field 2 is second ip. What i wanted to do if the user get one of ip address in field 1 and&amp;nbsp; get any ip address in the field 2 then it will alert. But if the user only get ip address in field 1 and did not get ip address in field2 it will not alert. I have multiple ip address in field 1 and only 4 ip address in field 2. Thank you&lt;!--  /data/user/0/com.samsung.android.app.notes/files/clipdata/clipdata_bodytext_210114_172305_471.sdocx  --&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 09:30:19 GMT</pubDate>
    <dc:creator>jlayson</dc:creator>
    <dc:date>2021-01-14T09:30:19Z</dc:date>
    <item>
      <title>Alerting using inputlookup</title>
      <link>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535796#M10113</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi all, im new in splunk, i was wondering if you can help me. This is&amp;nbsp; the scenario, im using inputlookup. I have csv&amp;nbsp; file with 2 fields field1 is original ip then field 2 is second ip. What i wanted to do if the user get one of ip address in field 1 and&amp;nbsp; get any ip address in the field 2 then it will alert. But if the user only get ip address in field 1 and did not get ip address in field2 it will not alert. I have multiple ip address in field 1 and only 4 ip address in field 2. Thank you&lt;!--  /data/user/0/com.samsung.android.app.notes/files/clipdata/clipdata_bodytext_210114_172305_471.sdocx  --&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 09:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535796#M10113</guid>
      <dc:creator>jlayson</dc:creator>
      <dc:date>2021-01-14T09:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting using inputlookup</title>
      <link>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535798#M10114</link>
      <description>&lt;P&gt;Where is "user" coming from (given that your csv only contains ip addresses)?&lt;/P&gt;&lt;P&gt;First you need to build a search query that returns the result you want to alert on. Do you have this already?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 09:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535798#M10114</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-01-14T09:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting using inputlookup</title>
      <link>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535801#M10115</link>
      <description>&lt;P&gt;We already have an alert , i just need to add that on the alert as an update.&amp;nbsp; The user will use there own IP address which is&amp;nbsp; indicated in field 1 then&amp;nbsp; the field 2 are 4 address that are not allowed to use if they are using any of the ip address on field1&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 09:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535801#M10115</guid>
      <dc:creator>jlayson</dc:creator>
      <dc:date>2021-01-14T09:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alerting using inputlookup</title>
      <link>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535806#M10116</link>
      <description>&lt;P&gt;Can you share what you currently have?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 10:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerting-using-inputlookup/m-p/535806#M10116</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-01-14T10:12:59Z</dc:date>
    </item>
  </channel>
</rss>

