Alerting

Verify Splunk Alert

nebel
Communicator

Hi,

I think I have a quiet complicated request.

Lets say I have the following event, which contains

LDAP error for hostXYZ

It is a real-time search configured which is triggering the words LDAP AND error.

Now I want to check before the alert appear, if the hostXYZ is valid. So all hosts which generates the event with error and LDAP should checked against a lookup which contains a table if the host is valid.

Thank you very much

Tags (2)
0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

You'll need to extract a field for the hostname. Then you can define a lookup which has the details of valid hosts. You could also consider tags. Finally tie it all together by adding either tag= or lookup= to your search.

View solution in original post

0 Karma

dart
Splunk Employee
Splunk Employee

You'll need to extract a field for the hostname. Then you can define a lookup which has the details of valid hosts. You could also consider tags. Finally tie it all together by adding either tag= or lookup= to your search.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...