Other Usage

How to set up a Splunk Alert if the field value is changed?

ud2110
Observer

Hi 

Need help on the below:

 

I have 2 field values for Status as RUNNING and SUCCESS. I want to generate 1st alert when the status becomes RUNNING for current day and the 2nd alert when the status get changed to SUCESS. 

I don't want  duplicate alerts till the time status is not getting changed

 

Thanks

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you try to use input-/outputlookup to keep track if you have found those already on current day?
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...