Splunk Observability Cloud

How to create a custom event detector?

niemi_splunk
Explorer

Hi,

I want to create a detector based on a custom event ingested using the API. I can select the eventType value as the signal but the conditions are all about signal values which obviously do not apply to an event.  

Any ideas?

Labels (1)

neilh
Engager

I would also like to know this. This seems like an obvious use case, but I can find no  information about how to achieve this in the documentation. 

If this is not possible, it makes the whole concept of custom events pretty useless IMO.

@niemi_splunk did you ever find a solution for this?

 

@bishida  @jha @matt  Do you know if this is possible?

Thanks

0 Karma

niemi_splunk
Explorer

I turned to write the events into a log file and used Log Pipeline Management to Metriczise them

0 Karma

neilh
Engager

Thanks for the response @niemi_splunk , much appreciated. 

Glad you found a working around. Unfortunately this won't work for me, as we're using Log Observer Connect, and Log Management Pipelines are not available, neither are metricised logs (unlike with the Log Observer entitlement).

I will wait and see if the others I tagged have any suggestions. 

0 Karma

bishida
Splunk Employee
Splunk Employee

Hi neilh,

I might be able to help point you in the right direction if I understand your use case better. Could you describe your scenario, what it is you're monitoring, and what you're trying to detect? We might just need a different approach to achieve your goal.

Generally speaking, detectors are built from signals and events add context to signals. So, events and signals are not the same thing.  Detectors can monitor signals and they can create events.

Here is a snippet from this documentation page that may help clarify.

https://docs.splunk.com/Observability/alerts-detectors-notifications/create-detectors-for-alerts.htm...

bishida_0-1685029645521.pngbishida_0-1685029645521.png

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...