Alerting

How to configure my email alert to exclude results?

super_virus
New Member

Hi ,

I have set up alerting on Java exceptions:

My search string:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java*

The above search emails us when a threshold for no of exceptions is met.

I need Spunk to exclude some specific exceptions, Spunk should ignore these multiple exceptions.

java.test.IllegArgumentException
java.test.IllegArgumentException
javat.persistence.testException

How do i get this done?

0 Karma
1 Solution

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

View solution in original post

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

super_virus
New Member

Thanks ! this works.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...