<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do we turn off alert email from source type=ps in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-we-turn-off-alert-email-from-source-type-ps/m-p/10294#M24</link>
    <description>&lt;P&gt;We get an alert from sourcetype=ps as a result of running this save search: &lt;CODE&gt;(authentication failure) OR (Account * too many attempts) OR (Failed password) startminutesago=5&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;We turned off the *nix app ps savedsearch but we still get the email. Here is the collapsed version of the alert: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;9/2/09 2:01:55.000 PM ... 126 lines
  omitted ... nagios 7033 5 0.0 00:00:00
  0.0 1216 54904 ? S 00:03 bash /usr/local/nagios/check_su_failures
  nagios 7038 3 75.3 00:00:02 0.0 400
  49936 ? R 00:03 cat /var/log/messages
  nagios 7039 7 59.0 00:00:01 0.0 624
  51096 ? R 00:03 grep
  authentication_failure nagios 7040 1
  0.0 00:00:00 0.0 588 51096 ? S 00:03 grep root nagios 7041 5 0.0 00:00:00
  0.0 572 51092 ? S 00:03 grep logapp-b&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Fri, 19 Mar 2010 23:45:29 GMT</pubDate>
    <dc:creator>Alan_Bradley</dc:creator>
    <dc:date>2010-03-19T23:45:29Z</dc:date>
    <item>
      <title>How do we turn off alert email from source type=ps</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-we-turn-off-alert-email-from-source-type-ps/m-p/10294#M24</link>
      <description>&lt;P&gt;We get an alert from sourcetype=ps as a result of running this save search: &lt;CODE&gt;(authentication failure) OR (Account * too many attempts) OR (Failed password) startminutesago=5&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;We turned off the *nix app ps savedsearch but we still get the email. Here is the collapsed version of the alert: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;9/2/09 2:01:55.000 PM ... 126 lines
  omitted ... nagios 7033 5 0.0 00:00:00
  0.0 1216 54904 ? S 00:03 bash /usr/local/nagios/check_su_failures
  nagios 7038 3 75.3 00:00:02 0.0 400
  49936 ? R 00:03 cat /var/log/messages
  nagios 7039 7 59.0 00:00:01 0.0 624
  51096 ? R 00:03 grep
  authentication_failure nagios 7040 1
  0.0 00:00:00 0.0 588 51096 ? S 00:03 grep root nagios 7041 5 0.0 00:00:00
  0.0 572 51092 ? S 00:03 grep logapp-b&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 19 Mar 2010 23:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-we-turn-off-alert-email-from-source-type-ps/m-p/10294#M24</guid>
      <dc:creator>Alan_Bradley</dc:creator>
      <dc:date>2010-03-19T23:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do we turn off alert email from source type=ps</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-we-turn-off-alert-email-from-source-type-ps/m-p/10295#M25</link>
      <description>&lt;P&gt;Try modifying your saved search to add a NOT statement for that sourcetype&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2010 23:46:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-we-turn-off-alert-email-from-source-type-ps/m-p/10295#M25</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2010-03-19T23:46:14Z</dc:date>
    </item>
  </channel>
</rss>

