Splunk Enterprise

Splunk light alerts to Splunk Enterprise

knalla
Path Finder

Hello,

we have splunk light platform only for few systems, Is there a way to send alerts from splunk light and ingest to splunk enterprise?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @knalla,
have you Splunk Light Free or Splunk Light?
If you have Splunk Light Free, Alerting isn't an available feature.
If you have Splunk Light, you can run an alert and send an event to Splunk Enterprise in many ways: via syslog, event in in a forwarded index or running a script.

Ciao.
Giuseppe

knalla
Path Finder

Yes, alerting is available, currently email alerts are configured.

0 Karma

knalla
Path Finder

Thanks gcusello, how can I configure syslog output for splunk light?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @knalla,
to use syslogs, you can follow this documentation:
https://docs.splunk.com/Documentation/Splunk/8.0.1/Forwarding/Forwarddatatothird-partysystemsd#Syslo...

Otherwise, you should configure something like an alert action that sends events across via HTTP Event Collector using the TA-Send_to_HEC App ( https://splunkbase.splunk.com/app/3508/ ) and enablig HEC on Splunk Enterprise (for more infos see https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/UsetheHTTPEventCollector ).

But maybe the easyest way is to send alerts to a mailbox and monitor this mailbox using the Splunk for IMAP App ( https://splunkbase.splunk.com/app/27/ ).

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...