How can I create alerts based on this app data received using API? How this app https://splunkbase.splunk.com/app/6960 alert if my data matches with the intel feeds?
Hi @aruncp333 ... this task should not any app specific.
Simply search for the particular data and count it, save it as alert with threshold of count >0..
pls let us know if you got the idea or any questions.. thanks.