All Apps and Add-ons

Trigger alert when over a proportion, but only include the select items on the attached CSV

MrMoody
Observer

I'm trying to create an alert that is triggered when event X is > 20% of a specific event type.

Once I have the trigger values, I want to include a CSV file that has the +20% transactions. So far I've been able to create the query to get the list for the CSV and a separate query that populates the necessary values for the alert condition, but I can't figure out how to attach a different CSV file to an alert, or to populate the alert with certain values while excluding others from the attachment that are necessary for the trigger condition.

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...