Alerting

How to configure my email alert to exclude results?

super_virus
New Member

Hi ,

I have set up alerting on Java exceptions:

My search string:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java*

The above search emails us when a threshold for no of exceptions is met.

I need Spunk to exclude some specific exceptions, Spunk should ignore these multiple exceptions.

java.test.IllegArgumentException
java.test.IllegArgumentException
javat.persistence.testException

How do i get this done?

0 Karma
1 Solution

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

View solution in original post

gokadroid
Motivator

Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:

index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)

OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException and so on.

super_virus
New Member

Thanks ! this works.

0 Karma
Get Updates on the Splunk Community!

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...