Splunk Enterprise

Searching and Alert in Monitoring Console

mathiasy123
Path Finder

I'm new to Splunk Enterprise, I did some searching and reporting for file log data, and from them, I implemented alerting and it worked well. Is it possible to make my alert show up in Monitoring Console Splunk Enterprise?

When I open the Splunk Enterprise Monitoring Console, all the searching and alert that I made not show up there, how to make my searching and alert that I made it show up in Monitoring Console?

 

Pict 1: Search and Alert in Monitoring Console (no search and alert that I made)

Pict 2: Search and Alert I made

 

mathiasy123_1-1593398440194.png

 

mathiasy123_0-1593398383204.png

 

 

Labels (2)
0 Karma
1 Solution

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

View solution in original post

0 Karma

anilchaithu
Builder

@mathiasy123 

The alert has to be created in monitoring console to show up. Since it is already created you can move it to monitoring console app.

Edit -> move -> select "monitoring console"

anilchaithu_0-1593401294311.png

 

anilchaithu_1-1593401331476.png

 

If this helps, up vote is appreciated.

0 Karma

mathiasy123
Path Finder

@anilchaithu  Why I don't have the "move" list?

mathiasy123_0-1593401475228.png

 

 

0 Karma

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

0 Karma

mathiasy123
Path Finder

@anilchaithu  

I am Admin,

I did and still not show up in "Alert Setup" Menu MC, only the default alert MC is show up 

mathiasy123_0-1593402487041.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

please check settings -> searches, reports and alerts

0 Karma

mathiasy123
Path Finder

Okay, it appeared!

So, the alert will be able to run in monitoring console automatically?

0 Karma

anilchaithu
Builder

Yes!!! It should run in monitoring console app.

0 Karma

mathiasy123
Path Finder

@anilchaithu 

 

I have been waiting for 3 hours, why the alert in MC not triggered?

mathiasy123_0-1593408305728.pngmathiasy123_1-1593408350430.pngmathiasy123_2-1593408358297.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

Did the search run? what is the schedule?

From the image shared, It looks like the alert has been scheduled every monday 6am. 

0 Karma

mathiasy123
Path Finder

So I need to wait untill tomorrow at 6 am?

0 Karma

mathiasy123
Path Finder

okay, thx so much !

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...