<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Raise alert for specific computers in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509071#M9314</link>
    <description>&lt;P&gt;Thanks. I will try using a lookup.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 13:07:45 GMT</pubDate>
    <dc:creator>wnyricsplunk</dc:creator>
    <dc:date>2020-07-14T13:07:45Z</dc:date>
    <item>
      <title>Raise alert for specific computers</title>
      <link>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509058#M9312</link>
      <description>&lt;P&gt;I would like to trigger an Alert when event 1074 (Windows Shutdown) is raised but only for specific computers. I have a group of about 50 servers and I would like to know if they shut down but I don't care about workstations in general. Since all events currently go to the same index I need a way to only trigger the alert when one of the servers raises the event. Short of a huge OR statement in my search, is there a way to do something like this?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 12:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509058#M9312</guid>
      <dc:creator>wnyricsplunk</dc:creator>
      <dc:date>2020-07-14T12:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Raise alert for specific computers</title>
      <link>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509069#M9313</link>
      <description>Unless there is some other unique attribute of the 50 servers, you have to use a bunch of ORs or a lookup file.</description>
      <pubDate>Tue, 14 Jul 2020 12:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509069#M9313</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-14T12:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Raise alert for specific computers</title>
      <link>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509071#M9314</link>
      <description>&lt;P&gt;Thanks. I will try using a lookup.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 13:07:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509071#M9314</guid>
      <dc:creator>wnyricsplunk</dc:creator>
      <dc:date>2020-07-14T13:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Raise alert for specific computers</title>
      <link>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509073#M9315</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;&lt;P&gt;You an create a macro to store the hosts that will expand into a filter, as you suggested, or you can use a lookup table that you pull into the search to use as a filter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Usesearchmacros" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesearchmacros&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-to-filter-hosts-by-lookup-table-and-show/td-p/223237" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-to-filter-hosts-by-lookup-table-and-show/td-p/223237&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 13:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Raise-alert-for-specific-computers/m-p/509073#M9315</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-14T13:15:57Z</dc:date>
    </item>
  </channel>
</rss>

