Alerting

correlation search variable doesn't work in my incident review

gwen
Loves-to-Learn Lots

hello,

i have a correlation search with variable that does'nt work

| stats count by host

| eval hello_world = host

when im looking in incident review, my alerte show $hello_word$ and not my values host.

Can you help me please ?

splunk ver 7.3.5

Labels (1)
0 Karma

gwen
Loves-to-Learn Lots

I thank you but I can not share much information because confidential.
It’s better to close the post.
Thanks for your help.
Excuse me for being upset.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen ,

as you like, but masking the information I don't think that you reveal your confidential information.

Anyway, good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gwen
Loves-to-Learn Lots

hello,

 

index=windows_srv EventCode=20005

| stats count by host

| search count >= 1

| eval server_impacted = host, tentative_number = count

| table server_impacted, tentative_number

 

and im using $server_impacted$ and $tentative_number$ in my correlation search.

 

then i see in tittle on my incident review : my message on $server_impacted$ instead my message on windowsservername

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen ,

let me understand: what are $server_impacted$ and $tentative_number$?

are they tokens to pass in a drilldown or what else?

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen,

sorry but I don't understand what you mean with variable.

A Correlation Search is an alert, so you canno pass a token to it.

Could you share your complete Correlation Search source code?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...