I have read this article which describes searching for high or critical notable events.
notable | where urgency="high" OR urgency="critical" | table _time source src dest user | eval computer=coalesce(src,dest)
Now i need a simple way to create a critical notable event to test.
How best to achieve this ?
You can also create a manual notable event in the UI. https://docs.splunk.com/Documentation/ES/4.7.2/Admin/Createnotablesmanually
I had to do something like this today try the following:
| eval user="skins", urgency="critical"
| sendalert notable