Alerting

health check for rules

karakutu
Path Finder

I have a lot of different alerts on our splunk. after every upgrade or change on splunk we just want to check if our alerts work well or not. 

how can we ensure the quality of the alerts?  how can we report if our alerts work properly as planed?

thanks

 

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You will need to inject data into Splunk that will trigger your alerts.  The data should also make it clear it is for test purposes so as to avoid causing alarm.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...