Alerting

how to pull a list of alerts which is having specific word?

iqbalintouch
Path Finder

Hi,

How can I pull a list or report of alerts which is having any of these specific words?
"purchase" OR "search" OR "booking"

Labels (1)
0 Karma

memarshall63
Communicator

Do you mean something like this?:

|rest /servicesNS/-/-/saved/searches 
| table title eai:acl.app eai:acl.owner actions search

So maybe with your criteria, it'd be:

|rest /servicesNS/-/-/saved/searches 
| table title eai:acl.app eai:acl.owner actions search
| where title LIKE "%Purchase%" OR title LIKE "%search%" OR title LIKE "%booking%"

Alerts generally have actions so you could add a filter for those, or there may be other ways to do it:

|rest /servicesNS/-/-/saved/searches 
| search NOT actions="" 
| table title eai:acl.app eai:acl.owner actions search 
| where title LIKE "%Purchase%" OR title LIKE "%search%" OR title LIKE "%booking%"
0 Karma

to4kawa
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...