Monitoring Splunk

Is there a way to dynamically control the severity of an alert?

danielbb
Motivator

We would like to dynamically populate the severity field, is it possible?

danielbb_0-1745941009851.png

 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What problem are you trying to solve this way? If you want to adjust criticality of an alert depending on an asset affected - that's the functionality of Enterprise Security.

livehybrid
Super Champion

Hi @danielbb 

No, you can only use those items in the dropdown. If you try and "Advanced Edit" the alert to use a field you get a validation error:

livehybrid_0-1745941526875.png

The only other thing you might be able to do is manually edit the savedsearches.conf and *try* using a field returned in there, however Your Mileage May Vary. This would also introduce management issues regarding the alert as it might make it impossible to edit in the UI - so whilst Im saying it might be possible, I wouldnt recommend it i'm afraid.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

gcusello
SplunkTrust
SplunkTrust

Hi @danielbb ,

could you better describe your request?

are you speaking of Splunk Enterprise or Enterprise Security?

ciao.

Giuseppe

Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...