All Apps and Add-ons

Lookup Editor and Alert Manager

logginz85
Explorer

Hi all.

We currently use Alert manager to annotate apps, and for several of them we have a drilldown that inputlookups a lookup table, edits it, then outputlookup it after. This means the team can use drilldowns to verify activity from users or suppress notifications for example.

Due to a small (but inevitable) incident where a lookup table was erased, we are now looking to utilise the Lookup Editor app so as to have some sort of version control.

However looking at it, it seems that version control is only maintained if the table is edited in the Lookup Editor app itself? Does this mean that drilldowns will not cause a backup to be made, and instead we'll have to have a link to this table in the app instead? 

If so thats fine, but can values from an alert be parsed through to edit fields already? Or would any modifications to the tables have to be copy/pasted?

Thanks in advance

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...