Alerting

How to set up an alert to display the results with verbose mode data, not fast mode?

kzhang201
New Member

I have set up a Cisco BGP syslog alert from Splunk. The BGP down event triggers correctly with all indexed data. See screenshot below:
alt text

But the Up message shows up with now indexed data in fast-mode:
alt text

If you view the message on the "up message", all data was indexed correctly in verbose mode, but not in fast-mode. How can I set up and alert in display the alert with verbose mode data?

0 Karma

somesoni2
Revered Legend

Give this query a try (in verbose mode)

tag=ROUTING facility=BGP Neighbor_IP=* Interface=* Descript=* State=* | table _time host facility Neighbor_IP Interface Descript State
0 Karma

kzhang201
New Member

Try that, still only received "down" event. the BGP up event never trigger

0 Karma

ECovell
Path Finder

Not sound contrite, but did you click on the down arrow next to the fast mode to see if verbose was an option?

Ernie.

0 Karma

kzhang201
New Member

yes, I did select it as verbose mode when create the search, but the output came back from alert is in Fast-mode.

0 Karma

ECovell
Path Finder

Did you happen to save the search after setting verbose?

0 Karma

kzhang201
New Member

I set it to verbose mode before I save the search.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...