Alerting

Is there a way to get Alert from adding lookup in query?

DougiieDee
Explorer
I am trying to get the alert when Excerption error happens but there are many hosts and services. In splunk the services and host arent arranged so manually I added the service name and hosts in csv file. is there a way or similar condition to get log events saying this serivce is getting error is this host with the message
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

@DougiieDee You can use lookup command prior to that you CSV shall be configured as lookup first assuming you did this already.

You SPL would something like this, when you say Message i hope you are referring to original event itself that's an _raw field in Splunk. host is the the common field hence you output your service. <lookup_name> and <your_search> are just place holders you have to replace them.

 

<your_search> 
| lookup <lookup_name> host OUTPUT service 
| table host service _raw

--

An upvote would be appreciated if this reply helps!

 

  

View solution in original post

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@DougiieDee You can use lookup command prior to that you CSV shall be configured as lookup first assuming you did this already.

You SPL would something like this, when you say Message i hope you are referring to original event itself that's an _raw field in Splunk. host is the the common field hence you output your service. <lookup_name> and <your_search> are just place holders you have to replace them.

 

<your_search> 
| lookup <lookup_name> host OUTPUT service 
| table host service _raw

--

An upvote would be appreciated if this reply helps!

 

  

0 Karma

DougiieDee
Explorer

Thank you worked perfectly. Also is there a way to limit the message like only take first 200 words?

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@DougiieDee 

 | head 200      should work.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @DougiieDee 

Can you explain bit more easily to understand.

0 Karma

DougiieDee
Explorer

i have a csv file which has host and service. In splunk host is there but not service. i wanted to search with the csv file so it displays as service host and message when the event happened. is there a way to do it?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...