<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic Alert from shown logs in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681826#M15856</link>
    <description>&lt;P&gt;Since you have given your problem statement in generic terms, I will answer in the same manner. You could look to use the eventstats command to add / copy the exception indicator to all events with the corresponding request id. Then you can filter the event by whether the exception indicator is present.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2024 09:20:55 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-03-25T09:20:55Z</dc:date>
    <item>
      <title>Dynamic Alert from shown logs</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681824#M15855</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to find errors/exceptions which has been raised within a timestamp and as per the request_id field mentioned in the logs(with every row) , need to fetch relevant logs in splunk&amp;nbsp; for that request_id and send this link to slack channel.&lt;/P&gt;&lt;P&gt;I am able to fetch all the errors/exception within timestamp and able to send to slack but I am not able to generate the relevant logs for the request_id mentioned with error/exception as it is dynamic in nature.&lt;/P&gt;&lt;P&gt;I am new to splunk so would like to understand, is this possible? if yes then could you please share relevant documentation so that I can understand it better.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 09:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681824#M15855</guid>
      <dc:creator>shraddhagrawal</dc:creator>
      <dc:date>2024-03-25T09:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Alert from shown logs</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681826#M15856</link>
      <description>&lt;P&gt;Since you have given your problem statement in generic terms, I will answer in the same manner. You could look to use the eventstats command to add / copy the exception indicator to all events with the corresponding request id. Then you can filter the event by whether the exception indicator is present.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 09:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681826#M15856</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-25T09:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Alert from shown logs</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681830#M15857</link>
      <description>&lt;P&gt;Thank you, let me check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 09:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamic-Alert-from-shown-logs/m-p/681830#M15857</guid>
      <dc:creator>shraddhagrawal</dc:creator>
      <dc:date>2024-03-25T09:33:44Z</dc:date>
    </item>
  </channel>
</rss>

