Splunk Enterprise Security

Automated scheduled notable events

SplunkNewbie18
New Member

Hi...

May I know if there is a way to schedule a set of fresh notable events to trigger (based on a fixed fields that's being input beforehand) every week, lets say Monday. Not based on correlation search/rules at the backend. Just a fresh new ones.

Example:
Monday 12am, a notable event triggers for Device A.
Monday 12am, a notable event triggers for Device B.

and process will recur every week.

Thanks!

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!