Reporting
Highlighted

How to get the Patterns Tab as an emailed scheduled report?

Builder

All,

LOVE the patterns tab. Is there a way for me to get that as an emailed scheduled search for my users?

0 Karma
Highlighted

Re: How to get the Patterns Tab as an emailed scheduled report?

Splunk Employee
Splunk Employee

Yes, you can. Just click a pattern, then click Create alert in the pattern information area on the right.

View solution in original post

Highlighted

Re: How to get the Patterns Tab as an emailed scheduled report?

Splunk Employee
Splunk Employee

Yup, and you can add | cluster t=0.3 labelonly=true labelfield=_patterns match=termset | findkeywords labelfield=_patterns dedup=true to any base search to identify clusters of events if you want to build your own view.