Alerting

If you execute the following btool command and check the result, which is the report or the alert?

human96
Communicator

I think savedsearches.conf contains information about alerts and reports. If you execute the following btool command and check the result, which is the report or the alert? I can't tell.

if i use splunk btool savedsearches list

<Question 1>

From the btool results, what parameters can I look at to determine that the stanza is a report?

<Question 2>

From the btool results, what parameters can I look at to determine that the stanza is an alert?

@somesoni2 

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

alert.track=0 means report.

alert.track=1 means alert.

If the value is auto that means Splunk would determine the value depending on the tracking settings of actions applied (for that see "actions.<some-action>" parameters in the btool output). - most of the time if you see actions its an alert.

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

alert.track=0 means report.

alert.track=1 means alert.

If the value is auto that means Splunk would determine the value depending on the tracking settings of actions applied (for that see "actions.<some-action>" parameters in the btool output). - most of the time if you see actions its an alert.

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are looking for description of savedsearches.con you see 

alert.track = <boolean> | auto
* Specifies whether to track the actions triggered by this scheduled search.
  * auto - determine whether to track or not based on the tracking setting of
    each action, do not track scheduled searches that always trigger actions.
  * true - force alert tracking.
  * false - disable alert tracking for this search.
* Default: auto

 I read this that it doesn’t  say 100% sure that this always define type of this saved searches. If it true then it’s an alert, but if it’s something else then it can be an alert or report.

r. Ismo

0 Karma

human96
Communicator

Thanks a lot @VatsalJagani  , you're  a saviour.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

human96
Communicator

hi @isoutamo  , Thanks alot 
i know yes you already answered the question yesterday.  but i didn't find it satisfactory.
@VatsalJagani  answer gave me the clarity how to distinguish between alert and the report.

 

Thanks for your response.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...