Hello,
is there anyway i can genrate alert and send mail from splunk .
for eg:- if there is an security-violation error on a particular switch like err-disable state if someone tried to connect a switch or router on a access port.
or
if a stack one of the switch went down splunk should send me an alert via email to my network team.
is it possible ?
Yes, it is possible. If you can search for it, you can alert on it. Once you've produced a search that finds the event(s) of interest, schedule it to run at some interval - every 15 minutes, for example. Then choose an alert trigger. I've found if number of events
is equal to
0
works best for my searches. Mark the Send email
box and fill in the addresses to which to send the alert.