Security

How can I create alerts based on this app data received using API

aruncp333
Explorer

How can I create alerts based on this app data received using API? How this app https://splunkbase.splunk.com/app/6960 alert if my data matches with the intel feeds?

Cyble Threat Intel 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @aruncp333 ... this task should not any app specific. 

Simply search for the particular data and count it, save it as alert with threshold of count >0.. 

pls let us know if you got the idea or any questions.. thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...