Alerting

Looking for solution of one alert calling script to execute second saved search

burwell
SplunkTrust
SplunkTrust

We want to do a search every minute on some logs. We want to identify those hosts whose events have http_code=5xx more than one percent of the time. And we want to see the actual events.

What I envisioned was one alert that would count the total events, count the 5xx events and when 5xx/total > 1% would alert and call a script that would perform a second search on the very same time event and show us the hosts and events that are involved.

We tried various things including evenstats, but it is too slow trying to do this in one search every minute. The search took too long.

I'm looking for a script called by search1 where I can call a named saved search2 with earliest/latest that I get from search1 and then have it alert.

Or maybe this is too complicated and there is a simpler way to go about this. Thanks!

0 Karma
1 Solution

dolivasoh
Contributor

Do you need to see all the events containing a 5xx error or would a sample do? if so, experiment with something like

| stats latest(_raw) as sample_event

If that's no good, I might suggest using a subsearch with append or appendcols

View solution in original post

burwell
SplunkTrust
SplunkTrust

If you answer the question I can then accept the answer...

0 Karma

dolivasoh
Contributor

Do you need to see all the events containing a 5xx error or would a sample do? if so, experiment with something like

| stats latest(_raw) as sample_event

If that's no good, I might suggest using a subsearch with append or appendcols

burwell
SplunkTrust
SplunkTrust

subsearch is the solution for me. I had never really used it before. That is exactly what I wanted. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...