Alerting

Alert Manager App - How to create a incident per result (row)

peterschloenske
Explorer

Hi,

I'm trying to create an incident within the Alert Manager App per result row of the generating search.
Let's say I have a search "Failed transactions by host". The result table looks like this:

_timehostfailed_transactions
2021-03-07 12:55:01host_a100
2021-03-07 12:55:01host_b200

 

It is easy to create an incident for "failed transactions" in general. But I would like to create incidents per host, that can be tracked individually.  I tried to achieve it by using $result.host$ as the title, but this did not work.

Does anyone know whether this is possible?


Labels (1)
0 Karma
1 Solution

peterschloenske
Explorer

I did not recognize that I saved it as report instead as an alert. As an alert, I can set "trigger for each result" to get it work

View solution in original post

0 Karma

peterschloenske
Explorer

I did not recognize that I saved it as report instead as an alert. As an alert, I can set "trigger for each result" to get it work

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...