Alerting

How to configure my email alert to exclude results?

super_virus
New Member

Hi ,

I have set up alerting on Java exceptions:

My search string:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java*

The above search emails us when a threshold for no of exceptions is met.

I need Spunk to exclude some specific exceptions, Spunk should ignore these multiple exceptions.

java.test.IllegArgumentException
java.test.IllegArgumentException
javat.persistence.testException

How do i get this done?

0 Karma
1 Solution

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

View solution in original post

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

super_virus
New Member

Thanks ! this works.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...