<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ALerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/ALerts/m-p/543785#M10320</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232452"&gt;@isin67&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your questions are just a little not so defined!&lt;/P&gt;&lt;P&gt;Anyway, about the first question, on Splunk you can create every kind of alert: missing of a message or a system, presence of a message, you can define thresholds, etc...&lt;/P&gt;&lt;P&gt;in few words, you have only to exactly define your alerts requirements and using Splunk you can realize them.&lt;/P&gt;&lt;P&gt;Then you can generate the action you like: eMail, script execution, list, etc...&lt;/P&gt;&lt;P&gt;About the second question, you have to define where the authentication messages are generated, how to identify them and how to take them: e.g. in windows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the login events are stored in WinEventLog,&lt;/LI&gt;&lt;LI&gt;they are defined with the EventCode (Login 4624, LogFail 4625, Logout 4634),&lt;/LI&gt;&lt;LI&gt;you can take them using the Splunk Technical Add-On for Windows.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The third answer is the same of the second,&amp;nbsp;you have to define where the authentication messages are generated, how to identify them and how to take them.&lt;/P&gt;&lt;P&gt;I think that you should follow some Splunk training to better understand how Splunk works, you could start from:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Splunk Fundamentals I (free course at &lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html" target="_blank"&gt;https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Splunk Search Tutorial (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then on YouTube you can find many introductive to Splunk videos.&lt;/P&gt;&lt;P&gt;If you could share more details, I could help you more.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 15 Mar 2021 07:28:59 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-03-15T07:28:59Z</dc:date>
    <item>
      <title>ALerts</title>
      <link>https://community.splunk.com/t5/Alerting/ALerts/m-p/543774#M10319</link>
      <description>&lt;P&gt;1.&amp;nbsp; Hi.. i would like to know&amp;nbsp; what types of alerts can be created using splunk ?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; how do i found that fingerprint login generates an event and how to log that event into splunk?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; how to make password alert for a website or particular app&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 05:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/ALerts/m-p/543774#M10319</guid>
      <dc:creator>isin67</dc:creator>
      <dc:date>2021-03-15T05:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: ALerts</title>
      <link>https://community.splunk.com/t5/Alerting/ALerts/m-p/543785#M10320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232452"&gt;@isin67&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your questions are just a little not so defined!&lt;/P&gt;&lt;P&gt;Anyway, about the first question, on Splunk you can create every kind of alert: missing of a message or a system, presence of a message, you can define thresholds, etc...&lt;/P&gt;&lt;P&gt;in few words, you have only to exactly define your alerts requirements and using Splunk you can realize them.&lt;/P&gt;&lt;P&gt;Then you can generate the action you like: eMail, script execution, list, etc...&lt;/P&gt;&lt;P&gt;About the second question, you have to define where the authentication messages are generated, how to identify them and how to take them: e.g. in windows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the login events are stored in WinEventLog,&lt;/LI&gt;&lt;LI&gt;they are defined with the EventCode (Login 4624, LogFail 4625, Logout 4634),&lt;/LI&gt;&lt;LI&gt;you can take them using the Splunk Technical Add-On for Windows.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The third answer is the same of the second,&amp;nbsp;you have to define where the authentication messages are generated, how to identify them and how to take them.&lt;/P&gt;&lt;P&gt;I think that you should follow some Splunk training to better understand how Splunk works, you could start from:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Splunk Fundamentals I (free course at &lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html" target="_blank"&gt;https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Splunk Search Tutorial (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then on YouTube you can find many introductive to Splunk videos.&lt;/P&gt;&lt;P&gt;If you could share more details, I could help you more.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 07:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/ALerts/m-p/543785#M10320</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-15T07:28:59Z</dc:date>
    </item>
  </channel>
</rss>

