Deployment Architecture

How to search to show only alerts out of maintenance mode?

chandankr
Path Finder

we have multiple site, site is n number, if any site fires 9251 that particular site should not be in the list as that site is in network Maintenace mode.any site can fires multiple alerts 9047 OR/AND 9251

now

9047 is fired from a b c d e
9251 is fired from c d


c d fired 9251 as this site or device is under maintenance

so
A 9047
B 9047
C 9251 9047
D 9251 9047
E 9047

so my output contain only
A 9047
B 9047
E 9047

how to write Splunk Queary for the same @

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats values(alert) as alerts by site
| where mvcount(alerts) == 1 AND alerts == 9047
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...