Splunk Search

Combining multiple searches

anirbanukil
Explorer

I have three different (unique) searches which sends out alerts in case certain conditions are met. I want to send an alert if all the three alerts (as mentioned above) are fired for an escalation scenario. Please advice how this can be achieved.

Tags (3)
0 Karma
1 Solution

imrago
Contributor

Perhaps you could create an alert which would search for those three alerts in

index="_audit" action="alert_fired"

View solution in original post

imrago
Contributor

Perhaps you could create an alert which would search for those three alerts in

index="_audit" action="alert_fired"

imrago
Contributor

index=_audit action="alert_fired" ss_name=Alert1 OR ss_name=Alert2 OR ss_name=Alert3 | stats dc(ss_name) as alerts

and you should fire the alert if alerts = 3

0 Karma

anirbanukil
Explorer

Thanks for the update but how can I search multiple alert names as an 'AND' condition.
Ex: Alert1 and Alert2 and Alert3 all have fired.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...