Alerting

Verify Splunk Alert

nebel
Communicator

Hi,

I think I have a quiet complicated request.

Lets say I have the following event, which contains

LDAP error for hostXYZ

It is a real-time search configured which is triggering the words LDAP AND error.

Now I want to check before the alert appear, if the hostXYZ is valid. So all hosts which generates the event with error and LDAP should checked against a lookup which contains a table if the host is valid.

Thank you very much

Tags (2)
0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

You'll need to extract a field for the hostname. Then you can define a lookup which has the details of valid hosts. You could also consider tags. Finally tie it all together by adding either tag= or lookup= to your search.

View solution in original post

0 Karma

dart
Splunk Employee
Splunk Employee

You'll need to extract a field for the hostname. Then you can define a lookup which has the details of valid hosts. You could also consider tags. Finally tie it all together by adding either tag= or lookup= to your search.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...