Alerting

How to set up an alert to display the results with verbose mode data, not fast mode?

kzhang201
New Member

I have set up a Cisco BGP syslog alert from Splunk. The BGP down event triggers correctly with all indexed data. See screenshot below:
alt text

But the Up message shows up with now indexed data in fast-mode:
alt text

If you view the message on the "up message", all data was indexed correctly in verbose mode, but not in fast-mode. How can I set up and alert in display the alert with verbose mode data?

0 Karma

somesoni2
Revered Legend

Give this query a try (in verbose mode)

tag=ROUTING facility=BGP Neighbor_IP=* Interface=* Descript=* State=* | table _time host facility Neighbor_IP Interface Descript State
0 Karma

kzhang201
New Member

Try that, still only received "down" event. the BGP up event never trigger

0 Karma

ECovell
Path Finder

Not sound contrite, but did you click on the down arrow next to the fast mode to see if verbose was an option?

Ernie.

0 Karma

kzhang201
New Member

yes, I did select it as verbose mode when create the search, but the output came back from alert is in Fast-mode.

0 Karma

ECovell
Path Finder

Did you happen to save the search after setting verbose?

0 Karma

kzhang201
New Member

I set it to verbose mode before I save the search.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...