All Apps and Add-ons

Lookup Editor and Alert Manager

logginz85
Explorer

Hi all.

We currently use Alert manager to annotate apps, and for several of them we have a drilldown that inputlookups a lookup table, edits it, then outputlookup it after. This means the team can use drilldowns to verify activity from users or suppress notifications for example.

Due to a small (but inevitable) incident where a lookup table was erased, we are now looking to utilise the Lookup Editor app so as to have some sort of version control.

However looking at it, it seems that version control is only maintained if the table is edited in the Lookup Editor app itself? Does this mean that drilldowns will not cause a backup to be made, and instead we'll have to have a link to this table in the app instead? 

If so thats fine, but can values from an alert be parsed through to edit fields already? Or would any modifications to the tables have to be copy/pasted?

Thanks in advance

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...