Alerting

"log event alert action" only logs one event

Path Finder

Hello,
I'm trying to setup the "log event alert action" within Splunk 6.4.2. I have it working except when the search (alert) returns more than one search, only one event gets logged.

Eg. Search -1h for malware IP addresses through the proxy, I'd like to create a "log event" for each result.

How can I do this?

Thanks

0 Karma
1 Solution

Path Finder

I figured it out. I needed to change the alert mode to "once per result"

View solution in original post

0 Karma

Path Finder

I figured it out. I needed to change the alert mode to "once per result"

View solution in original post

0 Karma