Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Alerts in Splunk Incidents

vijreddy30
Loves-to-Learn Everything

Hi team 

 

Created the Customize field in Splunk Alert mechanism, but in the incident receiving the single record only , Multiple records are not fetching the incident, please find the below  

 

location=KC xxxxxxxx Corporate Center||comments=Look into VPR Quality Docs Notifications Outlook email for Actual errors||description=Login to VPR Server and Quality Docs Vault to troubleshoot issue;
$result._time$ $result.host$ $result.Message$ $result.source$ $result.log_level$ $result.error_message$

 

Please help me 

0 Karma

tej57
Contributor

Hello @vijreddy30 ,

This may be possible because of following setting in the alert: Trigger

tej57_0-1717766038019.png

 

If this is set to Once, change it to "For each Result" and it should trigger alert for all the records.

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...