<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462018#M12597</link>
    <description>&lt;P&gt;Use this &lt;BR /&gt;
&lt;CODE&gt;index=nettraffic NOT ((source="a.b.c.d" dest="w.x.y.z") OR (dest="a.b.c.d" source="w.x.y.z"))&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2019 00:43:43 GMT</pubDate>
    <dc:creator>diogofgm</dc:creator>
    <dc:date>2019-10-17T00:43:43Z</dc:date>
    <item>
      <title>Splunk Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462016#M12595</link>
      <description>&lt;P&gt;I want to create an alert that will email us if we see any traffic that is not from a.b.c.d network communicating with w.x.y.z network (source or destination). I know I'm for sure missing stuff. &lt;/P&gt;

&lt;P&gt;Thank you to any help! &lt;BR /&gt;
Justin &lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 21:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462016#M12595</guid>
      <dc:creator>jdrogers83</dc:creator>
      <dc:date>2019-10-16T21:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462017#M12596</link>
      <description>&lt;P&gt;query data with NOT keyword i.e. index="your index" NOT source="x.x.x.x" AND destination="x.x.x.x". Trigger alert when Number of records &amp;gt; 0 or whatever threshold. &lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 22:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462017#M12596</guid>
      <dc:creator>saagar203</dc:creator>
      <dc:date>2019-10-16T22:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462018#M12597</link>
      <description>&lt;P&gt;Use this &lt;BR /&gt;
&lt;CODE&gt;index=nettraffic NOT ((source="a.b.c.d" dest="w.x.y.z") OR (dest="a.b.c.d" source="w.x.y.z"))&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 00:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alert/m-p/462018#M12597</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2019-10-17T00:43:43Z</dc:date>
    </item>
  </channel>
</rss>

