Alerting

How an alert can be raised separately for each event/result returned by a saved search?

AditiKulkarni
New Member

I have a saved search which returns multiple results/events at a time. I have configured this saved search to raise a real-time alert. I want the alert to be raised separately for each of the events returned by saved search for which i have set the alert mode as "Per result", but it is not giving the expected results. It is raising only a single alert for all of the events returned by the saved search at a time.

My scenario is: My saved search returns R1, R2, R3, ..., Rn results at a time. I want the alert to be raised separately for each of the results, say alert A1 for result R1, alert A2 for result R2 and so on. For this i have set an alert mode as "Per result", but the actual result I am getting is only alert A1 for all of the results R1, R2, R3,...., Rn. Could anyone help me in this? Is there any other way to achieve this?

0 Karma

bshuler_splunk
Splunk Employee
Splunk Employee
0 Karma

AditiKulkarni
New Member

Yes... I am following the exact procedure still i am getting only one alert for multiple search results and not separate alert for each of the result.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...