Splunk Search

How to Alert if an IP is added to a field

Loves-to-Learn Everything

I need some help with an alert i have been stuck on. I have a DBCONNECT lookup that returns a value once a day. This value contains 18 IPs at the moment all separated by "," - for example value=,,

I need an search i can create an alert off of if there is an IP added to this compared to when it was last ran. IE - search 1 at 6am had 5 IPs search 2 the next day has 6 IPs - alert.

right now i get the all the IPs in one field called "Value=" - looks like the below (ips changed for this post)


I basically need the alert to send our team an email letting us know an IP has been added and we should look into it.



Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!