Alerting

How an alert can be raised separately for each event/result returned by a saved search?

AditiKulkarni
New Member

I have a saved search which returns multiple results/events at a time. I have configured this saved search to raise a real-time alert. I want the alert to be raised separately for each of the events returned by saved search for which i have set the alert mode as "Per result", but it is not giving the expected results. It is raising only a single alert for all of the events returned by the saved search at a time.

My scenario is: My saved search returns R1, R2, R3, ..., Rn results at a time. I want the alert to be raised separately for each of the results, say alert A1 for result R1, alert A2 for result R2 and so on. For this i have set an alert mode as "Per result", but the actual result I am getting is only alert A1 for all of the results R1, R2, R3,...., Rn. Could anyone help me in this? Is there any other way to achieve this?

0 Karma

bshuler_splunk
Splunk Employee
Splunk Employee
0 Karma

AditiKulkarni
New Member

Yes... I am following the exact procedure still i am getting only one alert for multiple search results and not separate alert for each of the result.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...