Alerting

correlation search variable doesn't work in my incident review

gwen
Loves-to-Learn Lots

hello,

i have a correlation search with variable that does'nt work

| stats count by host

| eval hello_world = host

when im looking in incident review, my alerte show $hello_word$ and not my values host.

Can you help me please ?

splunk ver 7.3.5

Labels (1)
0 Karma

gwen
Loves-to-Learn Lots

I thank you but I can not share much information because confidential.
It’s better to close the post.
Thanks for your help.
Excuse me for being upset.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen ,

as you like, but masking the information I don't think that you reveal your confidential information.

Anyway, good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gwen
Loves-to-Learn Lots

hello,

 

index=windows_srv EventCode=20005

| stats count by host

| search count >= 1

| eval server_impacted = host, tentative_number = count

| table server_impacted, tentative_number

 

and im using $server_impacted$ and $tentative_number$ in my correlation search.

 

then i see in tittle on my incident review : my message on $server_impacted$ instead my message on windowsservername

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen ,

let me understand: what are $server_impacted$ and $tentative_number$?

are they tokens to pass in a drilldown or what else?

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gwen,

sorry but I don't understand what you mean with variable.

A Correlation Search is an alert, so you canno pass a token to it.

Could you share your complete Correlation Search source code?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...