Alerting

splunk user to create alerts from UI

vasanthi77
Explorer

Hi all ,

I am new to splunk so please consider even if it is basic one.
I have a requirement to build a dashboard where it has few dropdowns and fields. User should be able to configure an alert from the dropdown and fields he/she selected. Can someone please explain me how i can i achieve it.

Thanks in advance

0 Karma

DavidHourani
Super Champion

Hi @vasanthi77,

You cant configure the alert directly from the dashboard, you but you have two options :

1- Click on the magnifying glass at the bottom of the panel you want to use as an alert, open in search, and then save as an alert.

2- Create all your searches as reports, and add them to the dashboard as follows :
https://docs.splunk.com/Documentation/Splunk/7.2.6/SearchTutorial/Addreportstodashboard
Then anytime a user wants to turn a panel into an alert they can refer to the report and modify that.

Does that help answer your question ? Let me know if you need more details

Cheers,
David

0 Karma

vasanthi77
Explorer

Hi David ,
Thanks for the input. but after few digging into splunk concepts, I could find few options for the above requirement like , using setup.xml or "splunklib.client.Service" class. Can you provide more information on this if you have, Please.

0 Karma

vasanthi77
Explorer

Can anyone please help here 😞

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...