Alerting

Create email alert when a particular string/keyword is found in log event

navd
New Member

I am having couple of string to look for in log events and generate an alert when the matching string/keyword appears

Following are example keywords:-
ERROR - [] - Failed to create custom account for user
Code: Internal Server Error; Exception:
Internal Server Error; Exception: com.google.search.ts.exception:

So my current search look like this , but I want to know if there is any other way creating alert based on the string/keywords

index="abc" "ERROR - [] - Failed to create custom account for user" OR "Code: Internal Server Error; Exception: " OR "Internal Server Error; Exception: com.google.search.ts.exception: "

Tags (1)
0 Karma

amiftah
Communicator

Yes, In that case, you should extract the 4 strings in a field, and when you trigger the alert, send your field in your email: $result.yourfield$, and include this field in the search: index=foo error | table yourfield

0 Karma

amiftah
Communicator

I see all the strings contain "error" so maybe if you just save this search : index="abc" error as alert and choose send email as action will do the job..

0 Karma

navd
New Member

But , when I recieve the Email alert is it possible to include only the string that triggered(out of 4 other strings I am having) instead of displaying entire search string in email alert ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I would do it the same way.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...