<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic alert creation for TSM backup failures in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Dynamic-alert-creation-for-TSM-backup-failures/m-p/501979#M8943</link>
    <description>&lt;P&gt;Different sources should not be a problem in creating an alert.  Please explain what should trigger the alert.  What is to be "dynamic" about the alert?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2019 13:00:09 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-10-15T13:00:09Z</dc:date>
    <item>
      <title>Dynamic alert creation for TSM backup failures</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamic-alert-creation-for-TSM-backup-failures/m-p/501978#M8942</link>
      <description>&lt;P&gt;We are monitoring a folder which has multiple ~100 files. Each file is with single line of backup status. I have indexed all the files into splunk. Each line represent below is coming from different source.&lt;/P&gt;

&lt;P&gt;10/08/2019 23:00:00,,INC1111,SERVER1,Missed&lt;BR /&gt;
10/08/2019 22:00:00,,INC2210,SERVER2,Missed&lt;BR /&gt;
10/08/2019 21:00:00,10/08/2019 21:00:40,INCR2100,SERVER3,Failed 12&lt;BR /&gt;
10/08/2019 22:00:00,,INC2200,SERVER4,Missed&lt;BR /&gt;
10/08/2019 21:00:00,10/08/2019 21:00:40,INCR2100,SERVER5,Failed 12&lt;BR /&gt;
10/08/2019 21:00:00,,INC2100,SERVER6,Missed&lt;BR /&gt;
10/08/2019 21:00:00,,INC2100,SERVER7,Missed&lt;BR /&gt;
10/08/2019 21:00:00,10/08/2019 21:00:40,INCR2100,SERVER8,Failed 12&lt;BR /&gt;
10/08/2019 21:00:00,,INC2100,SERVER9,Missed&lt;BR /&gt;
10/08/2019 21:00:00,,INC2100,SERVER10,Missed&lt;BR /&gt;
10/08/2019 20:00:00,10/08/2019 20:05:02,INCR2000,SERVER11,Failed 12&lt;/P&gt;

&lt;P&gt;Requirement is to create an individual alert for each line here. Can this be possible with any dynamic query. I can create alert in bulk but that is not the soluation we are looking for.&lt;/P&gt;

&lt;P&gt;Is there is any possiblity to create a dynamic alert for each entry above from different files.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ramu Chittiprolu&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 11:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamic-alert-creation-for-TSM-backup-failures/m-p/501978#M8942</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-10-15T11:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic alert creation for TSM backup failures</title>
      <link>https://community.splunk.com/t5/Alerting/Dynamic-alert-creation-for-TSM-backup-failures/m-p/501979#M8943</link>
      <description>&lt;P&gt;Different sources should not be a problem in creating an alert.  Please explain what should trigger the alert.  What is to be "dynamic" about the alert?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 13:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Dynamic-alert-creation-for-TSM-backup-failures/m-p/501979#M8943</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-10-15T13:00:09Z</dc:date>
    </item>
  </channel>
</rss>

