I am setting up an alert for the first time.
My query ends with,
| table host,error
where "host" is host1, host2, host3 etc.. AND "error" is severe, critical, minor ..etc and blank rows as well.
Help is needed in the following two things.
I want my alert email to trigger only when,
example- "Host2 -Minor"
Hi @zacksoft,
Can you please try this
1. Host has some corresponding 'error' value .(Don't trigger when 'error' is NULL)
Can we add filter in your search?
like
YOUR_SEARCH | search error!=NULL | table host,error
The email header should contain Host name and the corresponding 'error' message.
add below line your alert in savedsearch.conf file:
[my_alert]
action.email.subject.alert = $result.host$ - $result.error$
Thanks
Hi @zacksoft,
you can try to search for error containing value instead of !=null value
<base_search>|search error=*|table host,error
set alert if result count>0
and you can set alert message as suggested by @kamlesh_vaghela
[my_alert] action.email.subject.alert = $result.host$ - $result.error$
it can be done via UI in Settings>>Searches, reports, and alerts and its stanza will get stored in ...<app_name>/local/savedsearches.conf
Hi @zacksoft,
Can you please try this
1. Host has some corresponding 'error' value .(Don't trigger when 'error' is NULL)
Can we add filter in your search?
like
YOUR_SEARCH | search error!=NULL | table host,error
The email header should contain Host name and the corresponding 'error' message.
add below line your alert in savedsearch.conf file:
[my_alert]
action.email.subject.alert = $result.host$ - $result.error$
Thanks
where can I find savedsearch.conf file ? I usually click on 'edit alert' option and set things in there !!!
in Settings>>Searches, reports, and alerts
you can create alert
Please check below path.
SPLUNK_HOME/etc/apps/My_APP/local/savedsearches.conf
SPLUNK_HOME/etc/users/USER_NAME/My_APP/local/savedsearches.conf
The Query's output sort of gives result like
Host1 - minor
Host1- minor
Host1 - minor
Host1 - critical
I am getting multiple alerts for 'minor' type. I cannot reduce the cron frequency becasue I don't wanna miss the 'critical' errros. Can we may be only select the 'distinct values' of error or suppress if the same error is repeating ....
Use |dedup error