Splunk Enterprise

Searching and Alert in Monitoring Console

mathiasy123
Path Finder

I'm new to Splunk Enterprise, I did some searching and reporting for file log data, and from them, I implemented alerting and it worked well. Is it possible to make my alert show up in Monitoring Console Splunk Enterprise?

When I open the Splunk Enterprise Monitoring Console, all the searching and alert that I made not show up there, how to make my searching and alert that I made it show up in Monitoring Console?

 

Pict 1: Search and Alert in Monitoring Console (no search and alert that I made)

Pict 2: Search and Alert I made

 

mathiasy123_1-1593398440194.png

 

mathiasy123_0-1593398383204.png

 

 

Labels (2)
0 Karma
1 Solution

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

View solution in original post

0 Karma

anilchaithu
Builder

@mathiasy123 

The alert has to be created in monitoring console to show up. Since it is already created you can move it to monitoring console app.

Edit -> move -> select "monitoring console"

anilchaithu_0-1593401294311.png

 

anilchaithu_1-1593401331476.png

 

If this helps, up vote is appreciated.

0 Karma

mathiasy123
Path Finder

@anilchaithu  Why I don't have the "move" list?

mathiasy123_0-1593401475228.png

 

 

0 Karma

anilchaithu
Builder

@mathiasy123 

what is your role. I guess, You need admin rights to move knowledge objects across apps.

If its not possible create the alert in MC app using run a search.

anilchaithu_0-1593401993204.png

 

0 Karma

mathiasy123
Path Finder

@anilchaithu  

I am Admin,

I did and still not show up in "Alert Setup" Menu MC, only the default alert MC is show up 

mathiasy123_0-1593402487041.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

please check settings -> searches, reports and alerts

0 Karma

mathiasy123
Path Finder

Okay, it appeared!

So, the alert will be able to run in monitoring console automatically?

0 Karma

anilchaithu
Builder

Yes!!! It should run in monitoring console app.

0 Karma

mathiasy123
Path Finder

@anilchaithu 

 

I have been waiting for 3 hours, why the alert in MC not triggered?

mathiasy123_0-1593408305728.pngmathiasy123_1-1593408350430.pngmathiasy123_2-1593408358297.png

 

0 Karma

anilchaithu
Builder

@mathiasy123 

Did the search run? what is the schedule?

From the image shared, It looks like the alert has been scheduled every monday 6am. 

0 Karma

mathiasy123
Path Finder

So I need to wait untill tomorrow at 6 am?

0 Karma

mathiasy123
Path Finder

okay, thx so much !

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...