All Apps and Add-ons

How to search the following EventCodes and Messages for Exchange in one alert with a inputlookup table.

sholmes
New Member

I don't want to create individual alerts for each EventCode and Message in the lookup table.
This is the search host="" source="WinEventLog:application" CategoryString="" [| inputlookup exchangecodes.csv | eval EventCode=EventCode | eval SourceName=SourceName | eval Message=Messages | table SourceName,EventCode,Message,host
Below is the exchangecodes.csv
EventCode Message SourceName LogName Type
100 Disk drive full Backup Exec System Recovery App warning
215 Backup stopped ESE App error
474 Problems reading EDB ESE App error
478 STM file corruption ESE App error
514 Out of log files ESE App warning
704 EDB defrag interrupted ESE App Information
8024 LDAP to DC failure MSExchangeAL App error
1005 SA unable to connect to Exch server MSExchangeIS App error
1159 Database error MSExchangeIS App error
8528 Mailbox full MSExchangeIS App warning
9514 Two objects, same proxy MSExchangeIS App warning
9519 database does not mount MSExchangeIS App error
9547 EDB not found MSExchangeIS App error
2000 Exchange MTA started? MSExchangeIS Mailbox Store App error
200 database checksum error MSExchangeMTA App warning
9411 Disk drive full MSExchangeMTA App error
1031 SA's task blocked MSExchangeSA App error
5007 Out of memory MSExchangeSA App error
9057 Cannot contact Global Catalog MSExchangeSA App error
9074 Directory Service Referral interface failed MSExchangeSA App error
9153 System Attendant error '0x8007203a' MSExchangeSA App error
9325 SMTP address invalid MSExchangeSA App error
9334 Offline address list not generated MSExchangeSA App error
3020 Forwarding loop MSExchangeTransport App error
68 Unable to initialize Scan Engine Symantec Mail Security for Microsoft Exchange App error
236 Quarantine has exceeded a set limit Symantec Mail Security for Microsoft Exchange App warning
292 License expiration Symantec Mail Security for Microsoft Exchange App warning
345 License expiration Symantec Mail Security for Microsoft Exchange App warning
12293 Shadow copy error VSS App error

0 Karma

bheffernan_splu
Splunk Employee
Splunk Employee

Something like this....You dont want inputlookup (the whole file), you only want the fields that match your search

host="" source="WinEventLog:application" CategoryString="" | lookup exchangecodes.csv | eval EventCode=EventCode | eval SourceName=SourceName | eval Message=Messages | table SourceName,EventCode,Message,host

Sample:
EventCode=* |lookup EventCodes.csv EventCode | table EventCode,LogName, desc

0 Karma

bheffernan_splu
Splunk Employee
Splunk Employee

host=myhost* source="WinEventLog:application" EventCode=* | lookup exchangecodes.csv EventCode |where isnotnull(Message) | table EventCode, Message, Type

0 Karma

Tune In & Win!

Don't miss out on your
chance to take home free
prizes by helping our players
save the Splunk Cloudom!

Dungeons & Data
Monsters: Splunk O11y
Day Editions Games
stream live:
5/4 at 6:30pm PST
5/5 at 7:00pm PST
on