<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combining two alerts into one condition in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505690#M9154</link>
    <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two conditions which I have been provided are two different main searches for my monitoring.&lt;/P&gt;&lt;P&gt;So when&amp;nbsp;the first search detects the server disconnection then we should get the email alert.&lt;/P&gt;&lt;P&gt;Same wise&amp;nbsp;for second search we need to receive the alert&amp;nbsp;after successful reconnection .&lt;/P&gt;&lt;P&gt;so we need to know how do we send these two alerts in different time frames by merging these main searches.&lt;/P&gt;&lt;P&gt;I request please kindly let me know the settings for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 09:41:37 GMT</pubDate>
    <dc:creator>ravikishore19</dc:creator>
    <dc:date>2020-06-23T09:41:37Z</dc:date>
    <item>
      <title>Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/471398#M8354</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Actually I have conflict while sending the alert, Please consider below scenario,&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;detecting and sending alert for when ever server gets disconnected from the network.&lt;/LI&gt;
&lt;LI&gt;after server gets connected to network and then I have configured one more alert condition for successful connection.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Now I want merge these two alerts into one alert condition like below,&lt;/P&gt;
&lt;P&gt;for example : &lt;BR /&gt;First server gets disconnected for 30 mins and Splunk will send the alert.&lt;BR /&gt;and after successful reconnection then using alert has to be sent to user by using one alert condition.&lt;/P&gt;
&lt;P&gt;Can you please help me out that how do I merge two alerts conditions into one condition.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;BR /&gt;Kishore&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 00:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/471398#M8354</guid>
      <dc:creator>ravikishore19</dc:creator>
      <dc:date>2020-06-09T00:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/504725#M9095</link>
      <description>&lt;P&gt;Dear Splunk team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please kindly suggest any idea on "&lt;/P&gt;&lt;DIV class="MessageSubjectIcons "&gt;&lt;DIV class="lia-message-subject"&gt;Combining two alerts into one condition".&lt;/DIV&gt;&lt;DIV class="lia-message-subject"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-subject"&gt;waiting for your kind response.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Jun 2020 03:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/504725#M9095</guid>
      <dc:creator>ravikishore19</dc:creator>
      <dc:date>2020-06-17T03:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/504740#M9096</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70262"&gt;@ravikishore19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share your searches?&lt;/P&gt;&lt;P&gt;Anyway, you can combine both the searches in one and give a different alert message in the two situations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 06:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/504740#M9096</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-17T06:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505128#M9125</link>
      <description>&lt;LI-CODE lang="markup"&gt;Hi Giuseppe,

Thanks for your reply,

Please consider the below two alert conditions,

Condition 1 : 
host="ServerName" source="WinEventLog:Blue Prism" "Message=A database error occurred while executing the statement"
"ComputerName=ServerName.alico.corp" The server cannot be found or cannot be accessed.

Condition 2 : 
host="ServerName" source="WinEventLog:Blue Prism"  "Resource successfully reconnected"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 19 Jun 2020 05:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505128#M9125</guid>
      <dc:creator>ravikishore19</dc:creator>
      <dc:date>2020-06-19T05:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505133#M9126</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70262"&gt;@ravikishore19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I'd prefer to have two different alerts than one because they are more manageble.&lt;/P&gt;&lt;P&gt;Only to be precise:&lt;/P&gt;&lt;P&gt;the search is the same in both the alerts:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;host="ServerName" source="WinEventLog:Blue Prism"&lt;/LI-CODE&gt;&lt;P&gt;the Condition 1 is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"A database error occurred while executing the statement"&lt;/LI-CODE&gt;&lt;P&gt;The Condition 2 is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"Resource successfully reconnected"&lt;/LI-CODE&gt;&lt;P&gt;So, you could run a search like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog host="ServerName" source="WinEventLog:Blue Prism"
| eval type=if(searchmatch("A database error occurred while executing the statement"),"Alert 1","Alert 2")
| dedup type
| table _time type&lt;/LI-CODE&gt;&lt;P&gt;A little hint: use always the index in the main search, it's quicker!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 06:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505133#M9126</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-19T06:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505458#M9148</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;I can see that you use alert condition1 in below,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog host="ServerName" source="WinEventLog:Blue Prism"
| eval type=if(searchmatch("A database error occurred while executing the statement"),"Alert 1","Alert 2")
| dedup type
| table _time type&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you include the Alert 2 in above search query.&lt;/P&gt;&lt;P&gt;Please kindly let me know the settings for sending email for above two alerts in different time frames.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 10:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505458#M9148</guid>
      <dc:creator>ravikishore19</dc:creator>
      <dc:date>2020-06-22T10:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505476#M9149</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70262"&gt;@ravikishore19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry I forgot a par of the answer:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog host="ServerName" source="WinEventLog:Blue Prism" ("A database error occurred while executing the statement" OR "Resource successfully reconnected")
| eval type=if(searchmatch("A database error occurred while executing the statement"),"Alert 1","Alert 2")
| dedup type
| table _time type&lt;/LI-CODE&gt;&lt;P&gt;if I correctly understood, the main search is the same and there'a a different string for condition 1 and 2.&lt;/P&gt;&lt;P&gt;In this way, you have the main search and the two conditions.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 12:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505476#M9149</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-22T12:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505690#M9154</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two conditions which I have been provided are two different main searches for my monitoring.&lt;/P&gt;&lt;P&gt;So when&amp;nbsp;the first search detects the server disconnection then we should get the email alert.&lt;/P&gt;&lt;P&gt;Same wise&amp;nbsp;for second search we need to receive the alert&amp;nbsp;after successful reconnection .&lt;/P&gt;&lt;P&gt;so we need to know how do we send these two alerts in different time frames by merging these main searches.&lt;/P&gt;&lt;P&gt;I request please kindly let me know the settings for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kishore&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 09:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505690#M9154</guid>
      <dc:creator>ravikishore19</dc:creator>
      <dc:date>2020-06-23T09:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Combining two alerts into one condition</title>
      <link>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505741#M9156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70262"&gt;@ravikishore19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I continue to ununderstand why you want only one search, in my opinion, it's better to have two alerts!&lt;/P&gt;&lt;P&gt;anyway, with the above search you have both the conditions in one alert.&lt;/P&gt;&lt;P&gt;Using it you can detect both the conditions, what do you need a correlation between them?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 13:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Combining-two-alerts-into-one-condition/m-p/505741#M9156</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-23T13:19:09Z</dc:date>
    </item>
  </channel>
</rss>

