Splunk Enterprise

Searching and Alert in Monitoring Console

mathiasy123
Path Finder

I'm new to Splunk Enterprise, I did some searching and reporting for file log data, and from them, I implemented alerting and it worked well. Is it possible to make my alert show up in Monitoring Console Splunk Enterprise?

When I open the Splunk Enterprise Monitoring Console, all the searching and alert that I made not show up there, how to make my searching and alert that I made it show up in Monitoring Console?

 

Pict 1: Search and Alert in Monitoring Console (no search and alert that I made)

Pict 2: Search and Alert I made

 

mathiasy123_1-1593398440194.png

 

mathiasy123_0-1593398383204.png

 

 

Labels (2)
0 Karma
1 Solution

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

View solution in original post

0 Karma

anilchaithu
Builder

@mathiasy123 

The alert has to be created in monitoring console to show up. Since it is already created you can move it to monitoring console app.

Edit -> move -> select "monitoring console"

anilchaithu_0-1593401294311.png

 

anilchaithu_1-1593401331476.png

 

If this helps, up vote is appreciated.

0 Karma

mathiasy123
Path Finder

@anilchaithu  Why I don't have the "move" list?

mathiasy123_0-1593401475228.png

 

 

0 Karma

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

0 Karma

mathiasy123
Path Finder

@anilchaithu  

I am Admin,

I did and still not show up in "Alert Setup" Menu MC, only the default alert MC is show up 

mathiasy123_0-1593402487041.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

please check settings -> searches, reports and alerts

0 Karma

mathiasy123
Path Finder

Okay, it appeared!

So, the alert will be able to run in monitoring console automatically?

0 Karma

anilchaithu
Builder

Yes!!! It should run in monitoring console app.

0 Karma

mathiasy123
Path Finder

@anilchaithu 

 

I have been waiting for 3 hours, why the alert in MC not triggered?

mathiasy123_0-1593408305728.pngmathiasy123_1-1593408350430.pngmathiasy123_2-1593408358297.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

Did the search run? what is the schedule?

From the image shared, It looks like the alert has been scheduled every monday 6am. 

0 Karma

mathiasy123
Path Finder

So I need to wait untill tomorrow at 6 am?

0 Karma

mathiasy123
Path Finder

okay, thx so much !

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...