Alerting

Dynamic Alert from shown logs

shraddhagrawal
New Member

Hi,

I need to find errors/exceptions which has been raised within a timestamp and as per the request_id field mentioned in the logs(with every row) , need to fetch relevant logs in splunk  for that request_id and send this link to slack channel.

I am able to fetch all the errors/exception within timestamp and able to send to slack but I am not able to generate the relevant logs for the request_id mentioned with error/exception as it is dynamic in nature.

I am new to splunk so would like to understand, is this possible? if yes then could you please share relevant documentation so that I can understand it better.

 

Thank you so much.

Labels (2)
0 Karma

shraddhagrawal
New Member

Thank you, let me check.

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Since you have given your problem statement in generic terms, I will answer in the same manner. You could look to use the eventstats command to add / copy the exception indicator to all events with the corresponding request id. Then you can filter the event by whether the exception indicator is present.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...