Alerting

Alert Manager App - How to create a incident per result (row)

peterschloenske
Explorer

Hi,

I'm trying to create an incident within the Alert Manager App per result row of the generating search.
Let's say I have a search "Failed transactions by host". The result table looks like this:

_timehostfailed_transactions
2021-03-07 12:55:01host_a100
2021-03-07 12:55:01host_b200

 

It is easy to create an incident for "failed transactions" in general. But I would like to create incidents per host, that can be tracked individually.  I tried to achieve it by using $result.host$ as the title, but this did not work.

Does anyone know whether this is possible?


Labels (1)
0 Karma
1 Solution

peterschloenske
Explorer

I did not recognize that I saved it as report instead as an alert. As an alert, I can set "trigger for each result" to get it work

View solution in original post

0 Karma

peterschloenske
Explorer

I did not recognize that I saved it as report instead as an alert. As an alert, I can set "trigger for each result" to get it work

0 Karma
Get Updates on the Splunk Community!

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...

Enterprise Security Content Update (ESCU) | New Releases

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise ...