All Apps and Add-ons

Lookup Editor and Alert Manager

logginz85
Explorer

Hi all.

We currently use Alert manager to annotate apps, and for several of them we have a drilldown that inputlookups a lookup table, edits it, then outputlookup it after. This means the team can use drilldowns to verify activity from users or suppress notifications for example.

Due to a small (but inevitable) incident where a lookup table was erased, we are now looking to utilise the Lookup Editor app so as to have some sort of version control.

However looking at it, it seems that version control is only maintained if the table is edited in the Lookup Editor app itself? Does this mean that drilldowns will not cause a backup to be made, and instead we'll have to have a link to this table in the app instead? 

If so thats fine, but can values from an alert be parsed through to edit fields already? Or would any modifications to the tables have to be copy/pasted?

Thanks in advance

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...