Splunk Search

How do I manage the content of my alert?

pdjhh
Communicator

Hi,

I have set up a couple of alerts and have chosen an inline table in the subsequent email. The contents of that table, however, seem almost totally random. Does anyone know where those fields come from and how they can be changed? I can see a display.events.fields setting in savedsearches, but I don't know if this has any bearing on it nor where the current fields in there came from. If I change them, it doesn't affect the content of the alert email.

The search is simply looking for values over a particular numeric threshold:

sourcetype=dbcsv  | eval percent_used=((LogFileSizeMB/DataFileSizeMB)*100) | eval percent_used=round(percent_used,1) | search percent_used>90

Ideally I'd like the email to contain a table that I can produce on a dashboard: _time, DataFileSizeMB, LogFileSizeMB, percent_used

Thanks.

0 Karma
1 Solution

somesoni2
Revered Legend

Use this as your alert search

sourcetype=dbcsv | table _time, DataFileSizeMB, LogFileSizeMB, percent_used| eval percent_used=((LogFileSizeMB/DataFileSizeMB)*100) | eval percent_used=round(percent_used,1) | search percent_used>90

View solution in original post

somesoni2
Revered Legend

Use this as your alert search

sourcetype=dbcsv | table _time, DataFileSizeMB, LogFileSizeMB, percent_used| eval percent_used=((LogFileSizeMB/DataFileSizeMB)*100) | eval percent_used=round(percent_used,1) | search percent_used>90

pdjhh
Communicator

OK great thanks that works. I had a table command in it previously and the whole alert wouldn't work but that must have been to do with some fields I had in the root search. This solution works and I can add what I need, thanks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...