Alerting

How to raise a Splunk alert notification for every event in a log?

akhilesh_chavva
New Member

Our requirement is to raise a Splunk notification to EVERY EVENT. How to achieve this?

Elaborate explanation: Consider below two entries are two events
xxx.xx.xx.xxx - - [01/Jul/2009:12:05:27 -0700] "GET /
  trade/app?action=logout HTTP/1.1" 200 2953
xxx.xx.xx.xxx - - [01/Jul/2009:12:04:30 -0700] "GET /
  trade/app?action=logout HTTP/1.1" 200 2953

I would like to raise a Splunk notification (in our case its ticket) for above two events (strictly speaking all the events).

Any suggestion would be appreciated.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could schedule an alert searching for index=yourdata and configure your alert actions accordingly. That would alert whenever there's data in that index with no further filtering.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...