Getting Data In

Change the alert action SNOW group from windows to sql team.

raghunandan1
Engager

Hi Team,

We have DB alerts for server sitpdb0033 are assigning to windows support team first , it needs to be assign to SQL team,
How to change the assignment group from windows support team to SQL team.

The index=mssql there are 30+ host's are configured. We want only change the group for this server sitpdb0033

we have using this SPL query:
index=mssql sourcetype="mssql:database" OR sourcetype="mssql:databases" state_desc!="ONLINE"

| eval assignment_group = case(like(source,"%mssql_mfg%"),"Winows_Support - Operations",1=1, "Sql_Production Support")

Can you please help on this requirement.

Thank you

Nandan

Labels (5)
Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @raghunandan1 ,

You can try below;

index=mssql sourcetype="mssql:database" OR sourcetype="mssql:databases" state_desc!="ONLINE" 
| eval assignment_group = case(host=="sitpdb0033","Sql_Production Support", like(source,"%mssql_mfg%"),"Winows_Support - Operations",1=1, "Sql_Production Support")
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

raghunandan1
Engager

Thank you for your suggestions,

As per your suggestions we have changed the SQL quiry. After changes results showing it's still "Winows_Support - Operations" group. 

Can you please help me here.

0 Karma

raghunandan1
Engager

As per your suggestions we have changed the SQL quiry. After changes results showing it's still "Winows_Support - Operations" group. 

Can you please help me here.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...