Reporting

How to get the Patterns Tab as an emailed scheduled report?

daniel333
Builder

All,

LOVE the patterns tab. Is there a way for me to get that as an emailed scheduled search for my users?

0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Yes, you can. Just click a pattern, then click Create alert in the pattern information area on the right.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Yes, you can. Just click a pattern, then click Create alert in the pattern information area on the right.

s2_splunk
Splunk Employee
Splunk Employee

Yup, and you can add | cluster t=0.3 labelonly=true labelfield=_patterns match=termset | findkeywords labelfield=_patterns dedup=true to any base search to identify clusters of events if you want to build your own view.

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...