Alerting

The field could not be added to log event alert action

hoangpt
Explorer

 

I have a problem that needs everyone to help me. I am trying to create log from an alert.
Please tell me how to separate the relevant fields from the raw data and then map it to that alert log, e.g. src_ip, servity...
 

120039370_2762800517341353_7177177067103308761_o.jpg

Labels (1)
0 Karma
1 Solution

dave_null
Path Finder

In the Event textfield, you can structure your generated event however you like. To insert values from the alert, use this format: (for example if you want to put src_ip field from the alert into the generated field)

$result.src_ip$

E.g. you can put this in the event text box:

Alert log - src_ip: $result.src_ip$ , severity: $result.severity$

View solution in original post

dave_null
Path Finder

In the Event textfield, you can structure your generated event however you like. To insert values from the alert, use this format: (for example if you want to put src_ip field from the alert into the generated field)

$result.src_ip$

E.g. you can put this in the event text box:

Alert log - src_ip: $result.src_ip$ , severity: $result.severity$

hoangpt
Explorer

Thank you for solving my problem 😄

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The alert is triggered by a query. The first row of the results of the query are available to be used in the log message you create. Therefore, you need to include all the information you want to be in your log in the results of the query that triggers the alert.

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...