Alerting

How an alert can be raised separately for each event/result returned by a saved search?

AditiKulkarni
New Member

I have a saved search which returns multiple results/events at a time. I have configured this saved search to raise a real-time alert. I want the alert to be raised separately for each of the events returned by saved search for which i have set the alert mode as "Per result", but it is not giving the expected results. It is raising only a single alert for all of the events returned by the saved search at a time.

My scenario is: My saved search returns R1, R2, R3, ..., Rn results at a time. I want the alert to be raised separately for each of the results, say alert A1 for result R1, alert A2 for result R2 and so on. For this i have set an alert mode as "Per result", but the actual result I am getting is only alert A1 for all of the results R1, R2, R3,...., Rn. Could anyone help me in this? Is there any other way to achieve this?

0 Karma

bshuler_splunk
Splunk Employee
Splunk Employee
0 Karma

AditiKulkarni
New Member

Yes... I am following the exact procedure still i am getting only one alert for multiple search results and not separate alert for each of the result.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...