| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        I am configuring SNMP traps based off of scheduled searches - does Splunk log this whenever a trap is generated? I as...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I pushed multiple saved searches from the deployment head to many production deployment clients. On the clients, I ca...
        
       
      | 
   
		
		2
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        This was a question from IRC: 
  How do I get rid of recurring "Error in 'SearchOperator:loadjob': Cannot find artifa...
        
       
      | 
   
		
		4
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi. I have scheduled a search to run on midnight, and I need to send a mail if the number of returned events is great...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I've got a saved search that's emailing me results up to this morning it was sending the results in a table with the ...
        
       
         
           by 
           
                
                    
                        thepocketwade
                    
                
           
             
             
               Path Finder
             
           
           in
           Alerting
           
           
              
               09-14-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am using the Manager to set-up a saved search/alert. Splunk runs a script every so often with an output like this: ...
        
       
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Dear 
  I search cmd: 
  sourcetype="access_combined" clientip="192.0.1.42" | sendemail to="teng.johnny@msa.hinet.net...
        
       
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have a handful of scheduled searches that a client would like emailed. They want to see the results in the email an...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Is it possible to add data from a search to the subject line of an email alert? Currently the subject defaults to the...
        
       
      | 
   
		
		3
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        C:\Program Files\Splunk\Python-2.6\Lib\smtpd.py??
        
       
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi, I am having trouble in create a condition for an alert that I would like. I have just started using Splunk and I ...
        
       
         
           by 
           
                
                    
                        gallantalex
                    
                
           
             
             
               Path Finder
             
           
           in
           Alerting
           
           
              
               08-25-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have saved the following search that generates a table and set it up to send me an email with the results. 
  The q...
        
       
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        There are a number of existing alerting conditions provided out of the box, such as populate_lookup, rss, email, and ...
        
       
      | 
   
		
		2
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Seeing the following error and no alerts are getting emailed although they are being triggered.  
  2010-08-10 14:00:...
        
       
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Alerting
           
           
              
               08-10-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hello, 
  I have an SMTP server that is unauthenticated. I have the server IP set up in Splunk Manager. I used this o...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Can someone explain the normal source of these errors? I've seen these errors in both the search.log (in the dispatch...
        
       
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I can get email alerting to work just fine on my *nix Splunk instance. In Windows, it doesn't seem to work and I see ...
        
       
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Alerting
           
           
              
               07-14-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I want to configure a saved search alert to trigger a script contained inside my app. The security measures only allo...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I'm looking for best practice when setting up a savedsearch email alerting when the alerting has the following requir...
        
       
      | 
   
		
		2
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Alert was triggered because of: 'Saved Search [fortyfor-test]: number of events(2)' 
  Apr 26 20:59:15 dist puppetd[1...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Anybody out there had experience trying to correlate events with Splunk. 
  A scenario would be like this: 
  (Source...
        
       
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Even though I'm able to view the sample PDF in mail settings, I see this in the bottom of email when attaching PDFs: ...
        
       
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi, 
  We get many alerts sent to us about cpu health under the email heading SERVER HEALTH ALERT - followed by tags....
        
       
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        We get an alert from sourcetype=ps as a result of running this save search: (authentication failure) OR (Account * to...
        
       
         
           by 
           
                
                    
                        Alan_Bradley
                    
                
           
             
             
               Path Finder
             
           
           in
           Alerting
           
           
              
               03-19-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I am using Splunk 4 and the email alerts that are sent to me have a bunch on junk in the 'To' and 'From' lines, like:...
        
       
      | 
   
		
		2
   
 | 	 
	  
	  1
	 
 |