<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to test Splunk alerts? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501708#M8940</link>
    <description>&lt;P&gt;Along the lines of your original idea to copy an event and modify it. You could do that and use &lt;CODE&gt;| collect&lt;/CODE&gt; command to write it back to your index.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Collect"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Collect&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 28 Mar 2020 00:11:44 GMT</pubDate>
    <dc:creator>anthonymelita</dc:creator>
    <dc:date>2020-03-28T00:11:44Z</dc:date>
    <item>
      <title>How to test Splunk alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501705#M8937</link>
      <description>&lt;P&gt;I configured an alert when a VPN connection is established from an IP that is located abroad. Now I would like to test if the alert works as expected. What is the best way of doing this? Can I for example copy a raw VPN login event, change the source IP, mark the event as alerttestevent and add it to Splunk to test the alert? &lt;/P&gt;

&lt;P&gt;Can this be automated somehow, i.e. when I adjust an alert I want to easily retest that everything still works as expected? I'm thinking about something like unit tests for Splunk alerts.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501705#M8937</guid>
      <dc:creator>spiced</dc:creator>
      <dc:date>2020-03-27T13:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to test Splunk alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501706#M8938</link>
      <description>&lt;P&gt;You can use the Eventgen App to generate events. Take a look this might be your answer.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1924/"&gt;https://splunkbase.splunk.com/app/1924/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501706#M8938</guid>
      <dc:creator>ckoltuk</dc:creator>
      <dc:date>2020-03-27T13:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to test Splunk alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501707#M8939</link>
      <description>&lt;P&gt;Thank you for the response, I'll take a closer look at the Eventgen App.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 14:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501707#M8939</guid>
      <dc:creator>spiced</dc:creator>
      <dc:date>2020-03-27T14:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to test Splunk alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501708#M8940</link>
      <description>&lt;P&gt;Along the lines of your original idea to copy an event and modify it. You could do that and use &lt;CODE&gt;| collect&lt;/CODE&gt; command to write it back to your index.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Collect"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Collect&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2020 00:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-test-Splunk-alerts/m-p/501708#M8940</guid>
      <dc:creator>anthonymelita</dc:creator>
      <dc:date>2020-03-28T00:11:44Z</dc:date>
    </item>
  </channel>
</rss>

